« Volver al listado

CVE-2025-7044

Estado: AnalizadaMedia (6.5)—

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-7044",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-7044",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-03T16:41:56.792010Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://launchpad.net/maas",
          "vendor": "Ubuntu",
          "product": "MAAS",
          "versions": [
            {
              "status": "affected",
              "version": "3.3.0",
              "lessThan": "3.3.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.4.0",
              "lessThan": "3.4.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.5.0",
              "lessThan": "3.5.9",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.6.0",
              "lessThan": "3.6.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "3.8.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "maas",
          "collectionURL": "https://canonical.com/maas",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-03T16:16:00.450",
  "references": [
    {
      "url": "https://bugs.launchpad.net/maas/+bug/2115714",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user.update websocket request and inject the is_superuser property set to true. The server improperly validates this input, allowing the attacker to self-promote to an administrator role. This results in full administrative control over the MAAS deployment."
    }
  ],
  "lastModified": "2026-06-17T10:04:09.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:maas:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4998723E-E15A-418C-96D6-411C2D337136",
              "versionEndExcluding": "3.3.11",
              "versionStartIncluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:maas:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D81D2C91-04DD-46DB-9BB5-D4092FAB7957",
              "versionEndExcluding": "3.4.9",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:maas:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02799C47-8A68-40C9-9061-F877F82CA4BA",
              "versionEndExcluding": "3.5.9",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:maas:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE9600AC-800F-49C3-8C8E-916FBD815E17",
              "versionEndExcluding": "3.6.2",
              "versionStartIncluding": "3.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}