CVE-2019-19230
9.8
CRITICAL · CVSS 3.1 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.76% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-12-09 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| broadcom | nolio |
| linux | linux kernel |
| microsoft | windows |
References
- http://packetstormsecurity.com/files/155631/CA-Nolio-6.6-Arbitrary-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Dec/16
- https://seclists.org/bugtraq/2019/Dec/16
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca20191209-01-security-notice-for-ca-nolio-release-automation.html?r=2
- http://packetstormsecurity.com/files/155631/CA-Nolio-6.6-Arbitrary-Code-Execution.html
- http://seclists.org/fulldisclosure/2019/Dec/16
- https://seclists.org/bugtraq/2019/Dec/16
- https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca20191209-01-security-notice-for-ca-nolio-release-automation.html?r=2
→ the Explorer · watch your stack · NVD