Vulnerabilities > CVE-2019-16328 - Unspecified vulnerability in Rpyc Project Rpyc 4.1.0/4.1.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
rpyc-project
nessus

Summary

In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure call that executes code for an RPyC service with default configuration settings.

Vulnerable Configurations

Part Description Count
Application
Rpyc_Project
2

Nessus

NASL familySuSE Local Security Checks
NASL idOPENSUSE-2020-685.NASL
descriptionThis update for python-rpyc to 4.1.5 fixes the following issues : Security issue fixed : - CVE-2019-16328: Fixed a missing protocol security check that could have led to code execution (boo#1152987).
last seen2020-05-31
modified2020-05-26
plugin id136881
published2020-05-26
reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/136881
titleopenSUSE Security Update : python-rpyc (openSUSE-2020-685)