« Volver al listado

CVE-2019-15719

Estado: ModificadaAlta (8)—

Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails to properly authenticate the message. This results in code execution as an arbitrary user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-15719",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.2,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-09T12:15:10.407",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/154782/PBS-Professional-19.2.3-Authentication-Bypass.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.hpcsec.com",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.hpcsec.com/2019/10/08/cve-2019-15719/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.pbspro.org/",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/154782/PBS-Professional-19.2.3-Authentication-Bypass.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.hpcsec.com",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.hpcsec.com/2019/10/08/cve-2019-15719/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.pbspro.org/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pbs_mom, which fails to properly authenticate the message. This results in code execution as an arbitrary user."
    },
    {
      "lang": "es",
      "value": "Altair PBS Professional versión hasta 19.1.2, permite la escalada de privilegios porque un atacante puede enviar un mensaje directamente a pbs_mom, que no puede autenticar el mensaje apropiadamente. Esto resulta en la ejecución de código como un usuario arbitrario."
    }
  ],
  "lastModified": "2026-06-17T02:20:56.410",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09FB9137-A031-45F8-9D6A-B379ED7D8B3C",
              "versionEndExcluding": "13.0.412",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8768C2F-30F7-448F-A57F-56CC17111787",
              "versionEndExcluding": "14.2.7",
              "versionStartIncluding": "14.0.0"
            },
            {
              "criteria": "cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C745F8B-5FC3-4F47-BA91-E6586E804E62",
              "versionEndExcluding": "18.2.5",
              "versionStartIncluding": "18.0.0"
            },
            {
              "criteria": "cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E166D7B-805E-4870-B255-FBF678B4A9D3",
              "versionEndExcluding": "19.1.3",
              "versionStartIncluding": "19.1.0"
            },
            {
              "criteria": "cpe:2.3:a:altair:pbs_professional:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43160393-5B5D-4C03-837D-5111BEAEF685",
              "versionEndExcluding": "19.2.4",
              "versionStartIncluding": "19.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}