PT-2022-20044 · Pypi · Python-Libnmap

Published

2022-05-04

·

Updated

2024-08-03

·

CVE-2022-30284

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions python-libnmap versions through 0.7.2
Description Remote command execution can occur in the python-libnmap package if used in a client application that does not validate arguments. The vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network.
Recommendations For versions through 0.7.2, consider validating arguments before calling NmapProcess to prevent remote command execution. As a temporary workaround, restrict the use of NmapProcess to trusted input data until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2022-30284
GHSA-QWQV-J7JR-4HP6
PYSEC-2022-42999

Affected Products

Python-Libnmap