« Volver al listado

CVE-2019-5916

Estado: ModificadaCrítica (9.8)—

Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-5916",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "D-CIRCLE inc.",
          "product": "POWER EGG",
          "versions": [
            {
              "status": "affected",
              "version": "(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-02-13T18:29:01.103",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN63860183/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://poweregg.d-circle.com/support/package/important/20190204_000780/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN63860183/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://poweregg.d-circle.com/support/package/important/20190204_000780/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-917"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and earlier, Ver 2.7 Government Edition Patch 7 and earlier, Ver 2.8 Patch 6 and earlier, Ver 2.8c Patch 5 and earlier, Ver 2.9 Patch 4 and earlier) allows remote attackers to execute EL expression on the server via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Problema de validación de entradas en POWER EGG (Ver 2.0.1, Ver 2.02 Parche 3 y anteriores, Ver 2.1 Parche 4 y anteriores, Ver 2.2 Parche 7 y anteriores, Ver 2.3 Parche 9 y anteriores, Ver 2.4 Parche 13 y anteriores, Ver 2.5 Parche 12 y anteriores, Ver 2.6 Parche 8 y anteriores, Ver 2.7 Parche 6 y anteriores, Ver 2.7 Government Edition Parche 7 y anteriores, Ver 2.8 Parche 6 y anteriores, Ver 2.8c Parche 5 y anteriores y Ver 2.9 Parche 4 y anteriores) permite que los atacantes remotos ejecuten una expresión EL en el servidor mediante vectores sin especificar."
    }
  ],
  "lastModified": "2026-06-17T02:38:24.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A2B5862-3977-4222-9534-78026B9A5717"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.0.2:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E282CD22-54F4-43B2-84AF-E42F40967A48"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.1:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F0239E6-A880-443A-A055-5049CD196847"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.2:patch7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0F259BD-5375-4AB5-9C4B-13E2EA57A74A"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.3:patch9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14C1B97D-B5FE-4408-BFAA-D62105BF5597"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.4:patch13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F79649C-F263-44E1-9330-515B93CDAD84"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.5:patch12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89261254-7B1E-498E-BC01-4AAD97B40BEF"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.6:patch8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98FA6176-758F-4604-8244-A5FC59E80D6C"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.7:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E5D871E-2713-476D-9C50-71A82DE09C8A"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.7:patch7:*:*:government:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EB2ED4D-9508-4EFD-ADD5-5F1EF7AEAC5F"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.8:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D310002-0446-476B-9D92-A2F04E1750AC"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.8c:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FA4E839-EC4D-45BC-98B4-F95C0B4F46C4"
            },
            {
              "criteria": "cpe:2.3:a:d-circle:power_egg:2.9:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF03BE87-B359-4631-A53B-5C0C8D9A4FAB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}