« Volver al listado

CVE-2021-32953

Estado: ModificadaCrítica (9.8)—

An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-32953",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-32953",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-16T15:56:37.488128Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "ics-cert@hq.dhs.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "MDT Software",
          "product": "MDT AutoSave",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "6.02.06",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "MDT Software",
          "product": "MDT AutoSave",
          "versions": [
            {
              "status": "affected",
              "version": "7.00",
              "lessThan": "7.04",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "MDT Software",
          "product": "AutoSave for System Platform (A4SP)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.01",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "MDT Software",
          "product": "A4SP",
          "versions": [
            {
              "status": "affected",
              "version": "5.00"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-01T23:15:09.703",
  "references": [
    {
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-189-02",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-21-189-02",
      "tags": [
        "Mitigation",
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login."
    },
    {
      "lang": "es",
      "value": "Un atacante podría usar comandos SQL para crear un nuevo usuario en MDT AutoSave versiones anteriores a v6.02.06, y actualizar los permisos del usuario, otorgando al atacante la capacidad de iniciar sesión"
    }
  ],
  "lastModified": "2026-06-17T03:53:51.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:auvesy-mdt:autosave:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F0612E0-E5EE-45B1-B49C-BD1296B9EACB",
              "versionEndExcluding": "6.02.06"
            },
            {
              "criteria": "cpe:2.3:a:auvesy-mdt:autosave:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8450FA45-0C07-42D5-B817-AC990579D4F6",
              "versionEndIncluding": "7.04",
              "versionStartIncluding": "7.00"
            },
            {
              "criteria": "cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDA02918-09D4-43B6-95E6-3023E3DEE57A",
              "versionEndExcluding": "4.01"
            },
            {
              "criteria": "cpe:2.3:a:auvesy-mdt:autosave_for_system_platform:5.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "682D5F51-4153-47C3-961C-6C5B4A124E3D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}