« Volver al listado

CVE-2022-34660

Estado: ModificadaCrítica (9.8)—

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter consist of a functionality that is vulnerable to command injection. This could potentially allow an attacker to perform remote code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-34660",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-34660",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-08T18:46:12.230495Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Teamcenter V12.4",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V12.4.0.15"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.0",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.0.0.10"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.1.0.10"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.2.0.9"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.3",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.3.0.5"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V14.0",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V14.0.0.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-10T12:15:12.200",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-759952.pdf",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-759952.pdf",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter consist of a functionality that is vulnerable to command injection. This could potentially allow an attacker to perform remote code execution."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en Teamcenter V12.4 (Todas las versiones anteriores a V12.4.0.15), Teamcenter V13.0 (Todas las versiones anteriores a V13.0.0.10), Teamcenter V13.1 (Todas las versiones anteriores a V13.1.0.10), Teamcenter V13.2 (Todas las versiones anteriores a V13.2.0.9), Teamcenter V13.3 (Todas las versiones anteriores a V13.3.0.5), Teamcenter V14.0 (Todas las versiones anteriores a V14.0.0.2). El servicio File Server Cache en Teamcenter consiste en una funcionalidad que es vulnerable a una inyección de comandos. Esto podría permitir a un atacante llevar a cabo una ejecución de código remota"
    }
  ],
  "lastModified": "2026-06-17T04:50:39.823",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AAD90FE-E22B-4801-8306-BD74485FCD1C",
              "versionEndExcluding": "12.4.0.15",
              "versionStartIncluding": "12.4"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76CF7820-950C-4DF1-BD78-6839BD44F4C6",
              "versionEndExcluding": "13.0.0.10",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6DA90DF-92D5-4091-97EC-B1BC0DD54981",
              "versionEndExcluding": "13.1.0.10",
              "versionStartIncluding": "13.1"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B6BC3EC-D245-410B-8332-3A5434CE75C3",
              "versionEndExcluding": "13.2.0.9",
              "versionStartIncluding": "13.2"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD3BE368-9523-45F2-B249-29B88F73C259",
              "versionEndExcluding": "13.3.0.5",
              "versionStartIncluding": "13.3"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A83E678F-3A9A-4F07-9D03-C224741877C4",
              "versionEndExcluding": "14.0.0.2",
              "versionStartIncluding": "14.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}