« Volver al listado

CVE-2022-1606

Estado: ModificadaMedia (4.3)—

Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1606",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-1606",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-28T18:05:17.779083Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@m-files.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 2.4,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 0.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@m-files.com",
      "affectedData": [
        {
          "vendor": "M-Files",
          "product": "M-Files Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.3.11164.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.3.11237.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-11-30T15:15:10.373",
  "references": [
    {
      "url": "https://empower.m-files.com/security-advisories/CVE-2022-1606",
      "source": "security@m-files.com"
    },
    {
      "url": "https://product.m-files.com/security-advisories/cve-2022-1606/",
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1606/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1606/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@m-files.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects."
    },
    {
      "lang": "es",
      "value": "La asignación de privilegios incorrecta en las versiones de M-Files Server en versiones anteriores a 22.3.11164.0 y versiones anteriores a 22.3.11237.1 permite al usuario leer objetos no administrados."
    }
  ],
  "lastModified": "2026-06-17T04:22:46.577",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C35E456-B63B-4972-AA77-7FF1884CB9C6",
              "versionEndExcluding": "22.3.11237.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@m-files.com"
}