peter bassill · operator
$ cve CVE-2022-34668 JSON

CVE-2022-34668 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 10.9% (pctl 96)

Patch early

A public exploit exists.

Description

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.9% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploityes
Published2022-08-29
Last modified2026-06-17

Affected (1)

VendorProduct
nvidianvflare

Public exploits

SourceTitleDate
exploit-dbNVFLARE < 2.1.4 - Unsafe Deserialization due to Pickle2023-03-25

References

→ the Explorer  ·  watch your stack  ·  NVD