Show plain JSON{"id": "CVE-2021-31926", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 2.8}]}, "published": "2021-04-30T20:15:09.363", "references": [{"url": "https://github.com/CubeCoders/AMP/issues/443", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/CubeCoders/AMP/issues/443", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-863"}]}], "descriptions": [{"lang": "en", "value": "AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open ports in the local system firewall by crafting an HTTP(S) request directly to the applicable API endpoint (despite not having permission to make changes to the system's network configuration)."}, {"lang": "es", "value": "AMP Application Deployment Service en CubeCoders AMP versiones 2.1.x anteriores a 2.1.1.2, permite a un usuario autenticado remoto abrir puertos en el firewall del sistema local al crear una petici\u00f3n HTTP(S) directamente en el endpoint de la API correspondiente (a pesar de no tener permiso para llevar a cabo cambios a la configuraci\u00f3n de red del sistema)."}], "lastModified": "2024-11-21T06:06:31.640", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:cubecoders:amp:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A96FE9F0-6B33-4347-8666-8D9C190A49B7", "versionEndExcluding": "2.1.1.2", "versionStartIncluding": "2.1.0"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}