CVE-2022-35411 is a critical Remote Code Execution (RCE) vulnerability affecting rpc.py through version 0.6.0. It arises from an insecure deserialization flaw where an unauthenticated client can force the application to process data using Python's pickle module, even though JSON is the default. With a CVSS score of 9.8 (Critical), this vulnerability allows an attacker to achieve complete compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction. While not currently listed in CISA's KEV catalog, a public exploit (EDB-50983) is available, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.4.2, <= 0.6.0CPE matchmatch criteria | cpe:2.3:a:rpc.py_project:rpc.py:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.