« Volver al listado

CVE-2023-5524

Estado: ModificadaAlta (7.3)—

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows

Remote Code Execution

via specific file types

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5524",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5524",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-28T18:31:37.963688Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@m-files.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@m-files.com",
      "affectedData": [
        {
          "vendor": "M-Files",
          "product": "Web Companion",
          "versions": [
            {
              "status": "affected",
              "version": "23.3",
              "lessThan": "23.10",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "23.8 LTS SR1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-20T07:15:17.717",
  "references": [
    {
      "url": "https://empower.m-files.com/security-advisories/CVE-2023-5524",
      "source": "security@m-files.com"
    },
    {
      "url": "https://product.m-files.com/security-advisories/cve-2023-5524/",
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2023-5524/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@m-files.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows \n\nRemote Code Execution\n\n via specific file types"
    },
    {
      "lang": "es",
      "value": "Lista negra insuficiente en M-Files Web Companion antes de la versión 23.10 y en las versiones de lanzamiento del servicio LTS anteriores a 23.8 LTS SR1 permite la ejecución remota de código a través de tipos de archivos específicos"
    }
  ],
  "lastModified": "2026-06-17T06:48:45.960",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:m-files:web_companion:*:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A13E967-9494-4FA8-AE96-503DACD92325",
              "versionEndExcluding": "23.8"
            },
            {
              "criteria": "cpe:2.3:a:m-files:web_companion:*:*:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8442CD82-5B17-4837-831B-BB1F4B4BC333",
              "versionEndExcluding": "23.10",
              "versionStartIncluding": "23.3"
            },
            {
              "criteria": "cpe:2.3:a:m-files:web_companion:23.8:-:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F039E21F-58D0-4BBC-B41E-EFE922009296"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@m-files.com"
}