CVE-2019-10123
Estado: ModificadaCrítica (9.8)—💥 Exploit
La inyección de SQL en Advanced InfoData Systems (AIS) ESEL-Server 67 (que es la base de la aplicación móvil de AIS logistics) permite que un atacante anónimo ejecute código arbitrario en el contexto del usuario de la base de datos MSSQL. El usuario por defecto para la base de datos es el usuario 'sa'.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 66%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Módulo de Metasploit (exploit fiable y al alcance de cualquiera) · AIS logistics ESEL-Server Unauth SQL Injection RCE
- Publicado en Exploit-DB · AIS logistics ESEL-Server - Unauthenticated SQL Injection Remote Code Execution (Metasploit) (30/4/2019)
Tecnologías afectadas (1)
CWE
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-10123",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-05-31T22:29:01.223",
"references": [
{
"url": "https://github.com/rapid7/metasploit-framework/pull/11641/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.ais.de",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/rapid7/metasploit-framework/pull/11641/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ais.de",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) allows an anonymous attacker to execute arbitrary code in the context of the user of the MSSQL database. The default user for the database is the 'sa' user."
},
{
"lang": "es",
"value": "La inyección de SQL en Advanced InfoData Systems (AIS) ESEL-Server 67 (que es la base de la aplicación móvil de AIS logistics) permite que un atacante anónimo ejecute código arbitrario en el contexto del usuario de la base de datos MSSQL. El usuario por defecto para la base de datos es el usuario 'sa'."
}
],
"lastModified": "2026-06-17T02:10:17.167",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:ais:logistic_software:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2704739D-18AE-4BC6-8C60-4B88CAC4A893",
"versionEndIncluding": "67"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:ais:esel-server:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B6831467-CCE8-4326-9252-636D7D660D4A"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}