« Volver al listado

CVE-2022-47559

Estado: ModificadaAlta (8.8)—

Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-47559",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve-coordination@incibe.es"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-47559",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-17T20:29:16.173766Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@incibe.es",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@incibe.es",
      "affectedData": [
        {
          "vendor": "Ormazabal",
          "product": "ekorCCP",
          "versions": [
            {
              "status": "affected",
              "version": "601j"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Ormazabal",
          "product": "ekorRCI",
          "versions": [
            {
              "status": "affected",
              "version": "601j"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*"
          ],
          "vendor": "ormazabal",
          "product": "ekorccp_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "601j"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*"
          ],
          "vendor": "ormazabal",
          "product": "ekorrci_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "601j"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-09-19T14:15:15.807",
  "references": [
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@incibe.es",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity."
    },
    {
      "lang": "es",
      "value": "** NO COMPATIBLE CUANDO ESTÁ ASIGNADO ** Falta de control del dispositivo sobre las solicitudes web en ekorCCP y ekorRCI, lo que permite a un atacante crear solicitudes personalizadas para ejecutar acciones maliciosas cuando un usuario inicia sesión, afectando a la disponibilidad, la privacidad y la integridad."
    }
  ],
  "lastModified": "2026-06-17T05:13:52.620",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34615054-34DD-469E-80FC-F5C3F74850AC"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ormazabal:ekorrci:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C5E73387-2229-4A85-A3A7-A0A2C1D74EA6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A8F0358-F8FA-4AEB-B88E-C56E2E965B7B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:ormazabal:ekorccp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "77B2D423-E767-495C-93C7-4C4B724BE3E3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve-coordination@incibe.es"
}