« Volver al listado

CVE-2024-11013

Estado: AplazadaAlta (7.2)—

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Inyección de comandos CLI via interfaz de gestión en dispositivo remoto (AV:N). Requiere privilegios altos (PR:H), característico de T1210. El impacto es ejecución arbitraria de comandos (CWE-77, descripción explícita).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-11013",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-11013",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-29T13:34:19.048337Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt-info@cyber.jp.nec.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "psirt-info@cyber.jp.nec.com",
      "affectedData": [
        {
          "vendor": "NEC Corporation",
          "product": "UNIVERGE IX",
          "versions": [
            {
              "status": "affected",
              "version": "from Ver9.2 to Ver10.10.21"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "UNIVERGE IX",
          "versions": [
            {
              "status": "affected",
              "version": "for Ver10.8 up to Ver10.8.27"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "UNIVERGE IX",
          "versions": [
            {
              "status": "affected",
              "version": "for Ver10.9 up to Ver10.9.14"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "NEC Corporation",
          "product": "UNIVERGE IX-R/IX-V",
          "versions": [
            {
              "status": "affected",
              "version": "Ver1.2.15 and earlier"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:nec:univerge_ix:*:*:*:*:*:*:*:*"
          ],
          "vendor": "nec",
          "product": "univerge_ix",
          "versions": [
            {
              "status": "affected",
              "version": "9.2",
              "versionType": "custom",
              "lessThanOrEqual": "10.10.21"
            },
            {
              "status": "affected",
              "version": "10.8",
              "versionType": "custom",
              "lessThanOrEqual": "10.8.27"
            },
            {
              "status": "affected",
              "version": "10.9",
              "versionType": "custom",
              "lessThanOrEqual": "10.9.14"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-29T08:15:03.923",
  "references": [
    {
      "url": "https://jpn.nec.com/security-info/secinfo/nv24-009_en.html",
      "source": "psirt-info@cyber.jp.nec.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt-info@cyber.jp.nec.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface."
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad de inyección de comandos en NEC Corporation UNIVERGE IX desde Ver9.2 hasta Ver10.10.21, desde Ver10.8 hasta Ver10.8.27, desde Ver10.9 hasta Ver10.9.14 y UNIVERGE IX-R/IX-V Ver1.2.15 y anteriores permite a un atacante inyectar comandos CLI arbitrarios para que se ejecuten en el dispositivo a través de la interfaz de administración."
    }
  ],
  "lastModified": "2026-06-17T06:56:53.087",
  "sourceIdentifier": "psirt-info@cyber.jp.nec.com"
}