CVE-2019-6446 details a critical remote code execution vulnerability in NumPy versions prior to 1.16.3, impacting NumPy and Fedora distributions. This flaw enables remote attackers to execute arbitrary code by exploiting unsafe deserialization of Python pickle objects through a crafted numpy.load call. With a CVSS score of 9.8 (CRITICAL), it poses a severe risk due to its network-based attack vector, low complexity, and complete impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, it is on the "Hot List: Active" with a high EPSS score and significant community discussion, indicating a high potential for exploitation despite no public exploit frameworks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.16.0CPE matchmatch criteria | cpe:2.3:a:numpy:numpy:*:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.