« Volver al listado

CVE-2023-35767

Estado: ModificadaAlta (7.5)—

In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-35767",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-35767",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-04T14:13:58.221210Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@puppet.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "Helix",
          "product": "Helix Core",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2023.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2023.1 Patch 2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2022.2 Patch 3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2022.1 Patch 6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2021.2 Patch 10",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Helix ",
          "product": "Helix Swarm",
          "versions": [
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2024.1 ",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:perforce:helix_core:-:*:*:*:*:*:*:*"
          ],
          "vendor": "perforce",
          "product": "helix_core",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2023.1\\/patch_2\\/",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2022.2\\/patch_3\\/",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2022.1\\/patch_6\\/",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2021.2\\/patch_10\\/",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-11-08T16:15:08.813",
  "references": [
    {
      "url": "https://perforce.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://perforce.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@puppet.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified.  Reported by Jason Geffner.  \n"
    },
    {
      "lang": "es",
      "value": "En las versiones de Helix Core anteriores a 2023.2, se identificó una Denegación de Servicio (DoS) remota no autenticada a través de la función de apagado. Reportado por Jason Geffner."
    }
  ],
  "lastModified": "2026-06-17T06:05:10.280",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:perforce:helix_core:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3D3C9B0-BDEA-4021-A6E5-22584345FD82",
              "versionEndExcluding": "2023.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}