« Volver al listado

CVE-2025-13774

Estado: AnalizadaAlta (8.8)—

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

SQL injection (CWE-89) en servicio remoto requiere PR:L (autenticación), compatible con T1210. Impactos: lectura de datos (T1005), manipulación de BD (T1565.001), potencial ejecución si la BD permite (T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-13774",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-13774",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-14T04:57:13.251308Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "vendor": "Progress Software",
          "product": "Flowmon ADS",
          "versions": [
            {
              "status": "affected",
              "version": "Flowmon ADS 12 versions prior to 12.5.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "Flowmon ADS 13 versions prior to 13.0.1",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-01-13T13:15:57.673",
  "references": [
    {
      "url": "https://community.progress.com/s/article/Flowmon-ADS-CVE-2025-13774",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad en las versiones de Progress Flowmon ADS anteriores a la 12.5.4 y la 13.0.1 donde una vulnerabilidad de inyección SQL permite a usuarios autenticados ejecutar consultas y comandos SQL no deseados."
    }
  ],
  "lastModified": "2026-06-17T08:34:43.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:progress:flowmon_anomaly_detection_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2C0B806-2C9A-4346-B73E-AE301E4E5B9D",
              "versionEndIncluding": "12.5.4",
              "versionStartIncluding": "12.0.0"
            },
            {
              "criteria": "cpe:2.3:a:progress:flowmon_anomaly_detection_system:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30CFE0AC-3BA0-45C9-83F1-780779492855",
              "versionEndIncluding": "13.0.1",
              "versionStartIncluding": "13.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}