{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-25T02:30:02.417","vulnerabilities":[{"cve":{"id":"CVE-2019-11031","sourceIdentifier":"cve@mitre.org","published":"2019-08-22T15:15:12.297","lastModified":"2026-06-17T02:12:09.590","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe. An attacker can upload files with a Setup-Files action, and then execute these files with SYSTEM privileges."},{"lang":"es","value":"Mirasys VMS versiones anteriores a V7.6.1 y versiones 8.x anteriores a V8.3.2, maneja inapropiadamente la funcionalidad de actualización automática de IDVRUpdateService2 en el archivo DVRServer.exe. Un atacante puede cargar archivos con una acción Setup-Files y entonces ejecutar estos archivos con privilegios de SYSTEM."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mirasys:mirasys_vms:*:*:*:*:*:*:*:*","versionEndExcluding":"7.6.1","matchCriteriaId":"DCBAA5E5-E6BD-44B0-B24A-45444A3ABEA5"},{"vulnerable":true,"criteria":"cpe:2.3:a:mirasys:mirasys_vms:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"8.3.2","matchCriteriaId":"5237DCB1-D58F-4945-A19D-0A8FB648BB0E"}]}]}],"references":[{"url":"https://www.kyberturvallisuuskeskus.fi/en/vulnerabilities-mirasys-vms-video-management-solution","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.kyberturvallisuuskeskus.fi/en/vulnerabilities-mirasys-vms-video-management-solution","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}