« Volver al listado

CVE-2026-40619

Estado: Pendiente de análisisAlta (7.8)—

A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.

This vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number.

Leer descripción completaMostrar menos

Consequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L + PR:L sin UI permite escalada local para acceder credenciales administrativas; CWE-532 (registro de información sensible) sustenta lectura de credenciales almacenadas.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-40619",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-40619",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-02T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@genetec.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@genetec.com",
      "affectedData": [
        {
          "vendor": "Genetec Inc.",
          "product": "Genetec Security Center",
          "versions": [
            {
              "status": "affected",
              "version": ">=5.7 SR6 <=5.10.4.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": ">5.10.4.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": ">=5.11.0.0 <=5.11.3.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": ">5.11.3.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": ">=5.12.0.0 <=5.12.2.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": ">5.12.2.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": ">=5.13.0.0 <=5.13.3.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": ">5.13.3.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": ">=5.14.0.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-02T16:16:39.127",
  "references": [
    {
      "url": "https://resources.genetec.com/security-advisories/vulnerability-affecting-security-center-systems-main-server-installations",
      "source": "security@genetec.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@genetec.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-532"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.\n\nThis vulnerability is associated with specific installation package builds rather than the product version identifier alone. Certain versions (including 5.10.4.0, 5.11.3.0, 5.12.2.0 and 5.13.3.0) were released with both vulnerable and remediated installation packages under the same version number.\n\nConsequently, version-based comparison alone is insufficient to determine exposure. Only installations performed using vulnerable builds are affected. Remediated builds can be distinguished using verified installation package hashes. For the complete list of fixed build hashes, refer to the security advisory section."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de alta seguridad que afecta a las instalaciones del servidor principal de Security Center ha sido identificada. Podría permitir a un atacante con privilegios de SO local en el servidor principal acceder a las credenciales de Administrador del Servidor. Un tercero contratado por Genetec encontró el problema. Actualmente no hay evidencia de explotación activa.\n\nEsta vulnerabilidad está asociada con compilaciones de paquetes de instalación específicas en lugar de solo el identificador de versión del producto. Ciertas versiones (incluyendo 5.10.4.0, 5.11.3.0, 5.12.2.0 y 5.13.3.0) fueron lanzadas con paquetes de instalación tanto vulnerables como remediados bajo el mismo número de versión.\n\nEn consecuencia, la comparación basada únicamente en la versión es insuficiente para determinar la exposición. Solo las instalaciones realizadas utilizando compilaciones vulnerables están afectadas. Las compilaciones remediadas pueden distinguirse utilizando hashes de paquetes de instalación verificados. Para la lista completa de hashes de compilaciones corregidas, consulte la sección de avisos de seguridad."
    }
  ],
  "lastModified": "2026-07-22T19:10:00.120",
  "sourceIdentifier": "security@genetec.com"
}