CVE-2022-24396
Estado: ModificadaAlta (7.8)—
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-306
Referencias
- http://packetstormsecurity.com/files/167560/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2022/Jun/38
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
- https://launchpad.support.sap.com/#/notes/3145987
- http://packetstormsecurity.com/files/167560/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2022/Jun/38
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
- https://launchpad.support.sap.com/#/notes/3145987
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-24396",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP Focused Run (Simple Diagnostics Agent)",
"versions": [
{
"status": "affected",
"version": "< >= 1.0"
},
{
"status": "affected",
"version": "< 1.58"
}
]
}
]
}
],
"published": "2022-03-10T17:46:09.270",
"references": [
{
"url": "http://packetstormsecurity.com/files/167560/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Missing-Authentication.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cna@sap.com"
},
{
"url": "http://seclists.org/fulldisclosure/2022/Jun/38",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/3145987",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "http://packetstormsecurity.com/files/167560/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Missing-Authentication.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2022/Jun/38",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/3145987",
"tags": [
"Permissions Required",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@sap.com",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations."
},
{
"lang": "es",
"value": "The Simple Diagnostics Agent - versiones 1.0 hasta 1.57, no lleva a cabo ninguna comprobación de autenticación para las funcionalidades a las que puede accederse por medio de localhost en el puerto http 3005. Debido a la falta de comprobaciones de autenticación, un atacante podría acceder a funcionalidades administrativas u otras privilegiadas y leer, modificar o eliminar información y configuraciones confidenciales"
}
],
"lastModified": "2026-06-17T04:31:45.817",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:simple_diagnostics_agent:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D15E1C0-4565-4829-B67C-BBDA7D2C8BFD",
"versionEndIncluding": "1.57",
"versionStartIncluding": "1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}