« Volver al listado

CVE-2022-47949

Estado: ModificadaCrítica (9.8)—

The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (9)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-47949",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-47949",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-14T18:36:31.417550Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-24T23:15:09.010",
  "references": [
    {
      "url": "https://github.com/PabloMK7/ENLBufferPwn",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/PabloMK7/ENLBufferPwn",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include Mario Kart 7 before 1.2, Mario Kart 8, Mario Kart 8 Deluxe before 2.1.0, ARMS before 5.4.1, Splatoon, Splatoon 2 before 5.5.1, Splatoon 3 before late 2022, Super Mario Maker 2 before 3.0.2, and Nintendo Switch Sports before late 2022."
    },
    {
      "lang": "es",
      "value": "La clase Nintendo NetworkBuffer, tal como se usa en Animal Crossing: New Horizons anterior a 2.0.6 y otros productos, permite a atacantes remotos ejecutar código arbitrario a través de un gran paquete UDP que provoca un desbordamiento del búfer, también conocido como ENLBufferPwn. La víctima deberá unirse a una sesión de juego con el atacante. Otros productos afectados incluyen Mario Kart 7 antes de 1.2, Mario Kart 8, Mario Kart 8 Deluxe antes de 2.1.0, ARMS antes de 5.4.1, Splatoon, Splatoon 2 antes de 5.5.1, Splatoon 3 antes de finales de 2022, Super Mario Maker 2 antes de 3.0 .2 y Nintendo Switch Sports antes de finales de 2022."
    }
  ],
  "lastModified": "2026-06-17T05:14:30.470",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nintendo:animal_crossing\\:_new_horizons:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E76851C-D70A-4134-B250-78B99985B211",
              "versionEndExcluding": "2.0.6"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:arms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A72CE5AE-CF5F-4C5B-8D68-A9FB5ADD0865",
              "versionEndExcluding": "5.4.1"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:mario_kart_7:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4666B65-0A4C-4B28-A46E-1968E75CDECC",
              "versionEndExcluding": "1.2"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:mario_kart_8:*:*:*:*:deluxe:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38F8B32D-954B-462D-993B-26B87A7C7F5A",
              "versionEndExcluding": "2.1.0"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:mario_kart_8:-:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19EA5E13-D11B-4573-B089-331124B7B698"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:splatoon:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BC0FC2B-E2B4-4652-AED5-4481DE5F3A4C"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:splatoon_2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B039788D-56ED-4309-A374-D11680FAAFD4",
              "versionEndExcluding": "5.5.1"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:splatoon_3:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76E2F213-1EB5-4781-9955-D45556F093E6"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:super_mario_maker_2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "736316DF-6291-4310-8FB5-F346F4DE2A7E",
              "versionEndExcluding": "3.0.2"
            },
            {
              "criteria": "cpe:2.3:a:nintendo:switch_sports:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55E863A6-6B3B-42C0-B70D-97D13EB23630"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}