Show plain JSON{"id": "CVE-2018-17931", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.2, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 6.8, "attackVector": "PHYSICAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 0.9}]}, "published": "2018-10-30T21:29:01.043", "references": [{"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-114-01", "tags": ["Third Party Advisory", "US Government Resource"], "source": "ics-cert@hq.dhs.gov"}, {"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-114-01", "tags": ["Third Party Advisory", "US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "ics-cert@hq.dhs.gov", "description": [{"lang": "en", "value": "CWE-284"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-284"}]}], "descriptions": [{"lang": "en", "value": "If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow code execution with root privileges."}, {"lang": "es", "value": "Si un atacante tiene acceso f\u00edsico a VGo Robot (las versiones 3.0.3.52164, 3.0.3.53662 y anteriores podr\u00edan haberse visto afectadas tambi\u00e9n), podr\u00eda ser capaz de alterar scripts, lo que permitir\u00eda la ejecuci\u00f3n de c\u00f3digo con privilegios root."}], "lastModified": "2024-11-21T03:55:14.010", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:vecna:vgo_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F86E7111-175E-42B3-8E86-391E0984B1BA", "versionEndIncluding": "3.0.3.52164"}, {"criteria": "cpe:2.3:o:vecna:vgo_firmware:3.0.3.53662:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "963BAE8B-59B4-4A28-82A6-8A9AF0F36B31"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:vecna:vgo:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A169276B-CA9C-44CC-9F3C-4969DD304520"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "ics-cert@hq.dhs.gov"}