PT-2022-10232 · Unknown · Inikulin Replicator

Yaniv Nizry

·

Published

2022-12-15

·

Updated

2025-04-21

·

CVE-2021-33420

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions inikulin replicator versions prior to 1.0.4
Description A deserialization issue in the inikulin replicator allows remote attackers to run arbitrary code via the fromSerializable function in the TypedArray object.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the fromSerializable function in the TypedArray object until a patch is available.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2021-33420
GHSA-HW46-VG6W-88FJ

Affected Products

Inikulin Replicator