CVE-2022-35411
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 46%
from disclosure to weapon21 days
Published on NVDJul 8
1st PoC+21d
exploitation probability
46%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/50983unverifiedgithubgithub.com/CSpanias/rpc-rce.py★ 2githubgithub.com/Neo-okami/CVE-2022-35411★ 0cve_referencepacketstormsecurity.com/files/167872/rpc.py-0.6.0-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.