// For flags

CVE-2009-3578

Autodesk Maya Script - Nodes Arbitrary Command Execution

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."

Autodesk Maya v8.0, v8.5, v2008, v2009, y v2010 y Alias Wavefront Maya v6.5 y v7.0 permite a atacantes remotos ejecutar código de su elección a través de archvio (1) .ma o (2) .mb que usa comando python de Maya Embedded Language (MEL) u otros comandos MEL no especificados, relacionado con (Script Nodes).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-10-07 CVE Reserved
  • 2009-11-23 CVE Published
  • 2009-11-23 First Exploit
  • 2023-07-18 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Autodesk
Search vendor "Autodesk"
Alias Wavefront Maya
Search vendor "Autodesk" for product "Alias Wavefront Maya"
6.5
Search vendor "Autodesk" for product "Alias Wavefront Maya" and version "6.5"
-
Affected
Autodesk
Search vendor "Autodesk"
Alias Wavefront Maya
Search vendor "Autodesk" for product "Alias Wavefront Maya"
7.0
Search vendor "Autodesk" for product "Alias Wavefront Maya" and version "7.0"
-
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.0
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.0"
2008
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.0
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.0"
2009
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.0
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.0"
2010
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.5
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.5"
2008
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.5
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.5"
2009
Affected
Autodesk
Search vendor "Autodesk"
Autodesk Maya
Search vendor "Autodesk" for product "Autodesk Maya"
8.5
Search vendor "Autodesk" for product "Autodesk Maya" and version "8.5"
2010
Affected