« Volver al listado

CVE-2019-15688

Estado: ModificadaMedia (6.1)—

Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-15688",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@kaspersky.com",
      "affectedData": [
        {
          "vendor": "Kaspersky",
          "product": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "up to 2020"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-26T16:15:12.243",
  "references": [
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#251119_1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vulnerability@kaspersky.com"
    },
    {
      "url": "https://support.kaspersky.com/general/vulnerability.aspx?el=12430#251119_1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass."
    },
    {
      "lang": "es",
      "value": "Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud hasta el 2020, el componente web protection no informó  adecuadamente al usuario sobre la amenaza de redireccionar a un sitio no seguro . Omisión."
    }
  ],
  "lastModified": "2026-06-17T02:20:52.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kaspersky:anti-virus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8765E8CA-25D7-45C4-A2B6-3E1CAB48D4BC",
              "versionEndIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:anti-virus:*:*:*:*:free:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE131770-352E-4D9A-BE68-AA02736FBC8A",
              "versionEndIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:internet_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09282512-31CB-4248-B57A-9CC77ED62642",
              "versionEndIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:security_cloud:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03CD0D9A-0787-4123-821D-89FB247FE002",
              "versionEndIncluding": "2020"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:small_office_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B11ACD5-3CFA-45EB-8505-D686EBB1E5FC",
              "versionEndIncluding": "7"
            },
            {
              "criteria": "cpe:2.3:a:kaspersky:total_security:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF1EF32C-3E9E-4CC6-90E0-D992FDEE984A",
              "versionEndIncluding": "2020"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerability@kaspersky.com"
}