« Volver al listado

CVE-2023-1997

Estado: ModificadaAlta (8.8)—

An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-1997",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-1997",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-02T14:14:19.906294Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3DS.Information-Security@3ds.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "3DS.Information-Security@3ds.com",
      "affectedData": [
        {
          "vendor": "Dassault Systèmes",
          "product": "SIMULIA 3DOrchestrate",
          "versions": [
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2021x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2021x.FP.CFA.2306"
            },
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2022x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2022x FP.CFA.2310"
            },
            {
              "status": "affected",
              "version": "Release 3DEXPERIENCE R2023x Golden",
              "versionType": "custom",
              "lessThanOrEqual": "Release 3DEXPERIENCE R2023x.FP.CFA.2314"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-08-28T16:15:08.627",
  "references": [
    {
      "url": "https://www.3ds.com/vulnerability/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3DS.Information-Security@3ds.com"
    },
    {
      "url": "https://www.3ds.com/vulnerability/advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3DS.Information-Security@3ds.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution."
    }
  ],
  "lastModified": "2026-06-17T05:29:13.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:3ds:3dexperience:r2021x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22C41137-50DF-4370-8A86-396061095A3A"
            },
            {
              "criteria": "cpe:2.3:o:3ds:3dexperience:r2022x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CB01B8A-297F-4B1C-A76A-1ED733E62A43"
            },
            {
              "criteria": "cpe:2.3:o:3ds:3dexperience:r2023x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E52A5F8A-665B-4AA7-89CD-19720D64718E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "3DS.Information-Security@3ds.com"
}