PT-2022-20044 · Pypi · Python-Libnmap
Published
2022-05-04
·
Updated
2024-08-03
·
CVE-2022-30284
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
python-libnmap versions through 0.7.2
Description
Remote command execution can occur in the python-libnmap package if used in a client application that does not validate arguments. The vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network.
Recommendations
For versions through 0.7.2, consider validating arguments before calling NmapProcess to prevent remote command execution. As a temporary workaround, restrict the use of NmapProcess to trusted input data until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python-Libnmap