CVE-2024-10224 is a critical vulnerability affecting Modules::ScanDeps versions prior to 1.36, impacting Debian and Ubuntu Linux distributions. A local attacker can achieve arbitrary shell command execution due to unsanitized input handling, specifically through "pesky pipes" or arbitrary string evaluation. With a CVSS score of 7.8 (High), this flaw allows for high impact to confidentiality, integrity, and availability with low attack complexity and no user interaction required. While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.36CPE matchmatch criteria | cpe:2.3:a:rschupp:modules\:\:scandeps:*:*:*:*:*:perl:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.