« Volver al listado

CVE-2026-22314

Estado: AplazadaAlta (7.9)—

Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856.

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-94 (Code Injection) + UI:R (interacción requerida) + vector CVSS de acceso de red con privilegios altos sugiere ejecución en cliente. Impacto: ejecución de código arbitrario en sistemas de otros usuarios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-22314",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-22314",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-20T12:29:31.474390Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.9,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "affectedData": [
        {
          "vendor": "Mesalvo",
          "product": "Meona Client Launcher Component",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "19.06.2020 15:11:49"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Mesalvo",
          "product": "Meona Server Component",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025.04 5+323020"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-20T11:16:26.057",
  "references": [
    {
      "url": "https://mesalvo.com/en/vdp/advisories/msa-2026-003.pdf",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vendor disputed record. The reported behaviour is documented \nadministrative functionality restricted to dedicated administrative \npermissions assigned by the operating hospital; its use by a permission \nholder is not a vulnerability. Unauthorised access to the functions is \naddressed under CVE-2026-0856.\n\nImproper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de control inadecuado de la generación de código ('Inyección de código') en el Componente Lanzador de Cliente Mesalvo Meona, Componente de Servidor Mesalvo Meona permite la ejecución de código en los sistemas de otros usuarios. Este problema afecta al Componente Lanzador de Cliente Meona: hasta el 19.06.2020 15:11:49; Componente de Servidor Meona: hasta el 2025.04 5+323020."
    }
  ],
  "lastModified": "2026-10-01T20:17:24.427",
  "sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}