CVE-2019-13656
9.8
CRITICAL · CVSS 3.1 · EPSS 5.8% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.82% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-09-06 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| broadcom | ca client automation |
| broadcom | ca workload automation ae |
References
- http://packetstormsecurity.com/files/154418/CA-Common-Services-Distributed-Intelligence-Architecture-DIA-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Sep/15
- https://casupport.broadcom.com/us/product-content/recommended-reading/security-notices/CA20190904-01--security-notice-for-ca-common-services-distributed-intelligence-architecture-dia.html
- https://seclists.org/bugtraq/2019/Sep/14
- http://packetstormsecurity.com/files/154418/CA-Common-Services-Distributed-Intelligence-Architecture-DIA-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Sep/15
- https://casupport.broadcom.com/us/product-content/recommended-reading/security-notices/CA20190904-01--security-notice-for-ca-common-services-distributed-intelligence-architecture-dia.html
- https://seclists.org/bugtraq/2019/Sep/14
→ the Explorer · watch your stack · NVD