Vulnerabilities > CVE-2022-40238 - Deserialization of Untrusted Data vulnerability in Cert Vince

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
cert
CWE-502

Summary

A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inject arbitrary pickle object as part of a user's profile. This can lead to code execution on the server when the user's profile is accessed.

Vulnerable Configurations

Part Description Count
Application
Cert
5

Common Weakness Enumeration (CWE)