Lucene search

K
cve[email protected]CVE-2009-3578
HistoryNov 24, 2009 - 5:30 p.m.

CVE-2009-3578

2009-11-2417:30:00
CWE-94
web.nvd.nist.gov
36
cve-2009-3578
autodesk maya
alias wavefront maya
remote code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.032 Low

EPSS

Percentile

91.3%

Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to β€œScript Nodes.”

Affected configurations

NVD
Node
autodeskalias_wavefront_mayaMatch6.5
OR
autodeskalias_wavefront_mayaMatch7.0
OR
autodeskautodesk_mayaMatch8.02008
OR
autodeskautodesk_mayaMatch8.02009
OR
autodeskautodesk_mayaMatch8.02010
OR
autodeskautodesk_mayaMatch8.52008
OR
autodeskautodesk_mayaMatch8.52009
OR
autodeskautodesk_mayaMatch8.52010

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.032 Low

EPSS

Percentile

91.3%