CVE-2018-1000045 describes a critical deserialization vulnerability (CWE-502) in NASA Singledop v1.0, specifically within its weather data library. This flaw allows for remote code execution when a victim opens a specially crafted radar data file. With a CVSS score of 7.8 (High), the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L), potentially leading to full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). While a fix is available in v1.1, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:nasa:singledop:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.