CVE-2026-22903
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.69%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1499.004Application or System Exploitationimpact80 %
Vector AV:N/PR:N/UI:N indica red sin autenticación (T1190). Stack buffer overflow en servidor web puede lograr RCE (T1059) o DoS (T1499.004) por crash del servicio.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-121
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-22903",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-22903",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-02-09T15:36:08.801691Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "WAGO",
"product": "0852-1322",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "2.64"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "0852-1328",
"versions": [
{
"status": "affected",
"version": "0.0.0",
"versionType": "semver",
"lessThanOrEqual": "2.64"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "0852-1322",
"versions": [
{
"status": "affected",
"version": "2.64"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "WAGO",
"product": "0852-1328",
"versions": [
{
"status": "affected",
"version": "2.64"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-09T08:16:10.103",
"references": [
{
"url": "https://certvde.com/de/advisories/VDE-2026-004",
"source": "info@cert.vde.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-121"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections."
},
{
"lang": "es",
"value": "Un atacante remoto no autenticado puede enviar una solicitud HTTP manipulada que contiene una cookie SESSIONID excesivamente larga. Esto puede desencadenar un desbordamiento de búfer de pila en el servidor lighttpd modificado, lo que provoca su caída y potencialmente permite la ejecución remota de código debido a la falta de protecciones de pila."
}
],
"lastModified": "2026-06-17T10:20:35.310",
"sourceIdentifier": "info@cert.vde.com"
}