BlackTreeIndependent security intelligence
← Back to the CVE catalogue
Full vulnerability report · 2023
CVE-2022-48564High confidence

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format

n/a · n/a

6.5MediumCVSS 3.1
Recommended action
Within 7 days

Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Select the national-authority views to include. The exact source language is shown on each matched advisory. Your choice is remembered on this device and encoded in the shareable URL.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2022-51260

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

What

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.

Why

The product does not properly control the allocation and maintenance of a limited resource.

How

An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Uncontrolled Resource Consumption → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
Required interaction required
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-400

CWE-400: Uncontrolled Resource Consumption. The product does not properly control the allocation and maintenance of a limited resource.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UIRequiredUser interaction: Another user must perform an action for exploitation to succeed.SUnchangedScope: The security impact remains within the vulnerable component's authority.CNoneConfidentiality impact: No direct loss is represented by this metric.INoneIntegrity impact: No direct loss is represented by this metric.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-400Public exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-W-2024-1086IBM QRadar SIEM: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Dateien zu manipulieren, seine Privilegien zu erweitern, einen Cross-Site-Scripting (XSS)-Angriff durchzuführen oder einen nicht spezifizierten Angriff auszuführen.

Official advisory
BSI · German · WID-SEC-W-2023-2119Python: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Python ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren oder vertrauliche Informationen offenzulegen.

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0864Multiples vulnérabilités dans VMware Tanzu

rg/CVERecord?id=CVE-2022-3602 Référence CVE CVE-2022-3786 https://www.cve.org/CVERecord?id=CVE-2022-3786 Référence CVE CVE-2022-3996 https://www.cve.org/CVERecord?id=CVE-2022-3996 Référence CVE CVE-2022-40735 https://www.cve.org/CVERecord?id=CVE-2022-40735 Référence CVE CVE-2022-4203 https://www.cve.org/CVERecord?id=CVE-2022-4203 Référence CVE CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2022-4304 Référence CVE CVE-2022-4450 https://www.cve.org/CVERecord?id=CVE-2022-4450 Référence CVE CVE-2022-45061 https://www.cve.org/CVERecord?id=CVE-2022-45061 Référence CVE CVE-2022-48560 https://www.cve.org/CVERecord?id=CVE-2022-48560 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-48565 https://www.cve.org/CVERecord?id=CVE-2022-48565 Référence CVE CVE-2022-48566 https://www.cve.org/CVERecord?id=CVE-2022-48566 Référence CVE CVE-2023-0215 https://www.cve.org/CVERecord?id=CVE-2023-0215 Référence CVE CVE-2023-0216 https://www.cve.org/CVERecord?id=CVE-2023-0216 Référence CVE CVE-2023-0217 https://www.cve.org/CVERecord?id=CVE-2023-0217 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-0401 https://www.cve.org/CVERecord?id=CVE-2023-0401 Référence CVE CVE-2023-0464 https://www.cve.org/CVERecord?id=CVE-2023-04

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0661Multiples vulnérabilités dans les produits Splunk

d?id=CVE-2022-38398 Référence CVE CVE-2022-38648 https://www.cve.org/CVERecord?id=CVE-2022-38648 Référence CVE CVE-2022-40146 https://www.cve.org/CVERecord?id=CVE-2022-40146 Référence CVE CVE-2022-41704 https://www.cve.org/CVERecord?id=CVE-2022-41704 Référence CVE CVE-2022-41881 https://www.cve.org/CVERecord?id=CVE-2022-41881 Référence CVE CVE-2022-42004 https://www.cve.org/CVERecord?id=CVE-2022-42004 Référence CVE CVE-2022-42890 https://www.cve.org/CVERecord?id=CVE-2022-42890 Référence CVE CVE-2022-45061 https://www.cve.org/CVERecord?id=CVE-2022-45061 Référence CVE CVE-2022-48285 https://www.cve.org/CVERecord?id=CVE-2022-48285 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-4899 https://www.cve.org/CVERecord?id=CVE-2022-4899 Référence CVE CVE-2023-0833 https://www.cve.org/CVERecord?id=CVE-2023-0833 Référence CVE CVE-2023-1370 https://www.cve.org/CVERecord?id=CVE-2023-1370 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-2023-27043 Référence CVE CVE-2023-34462 https://www.cve.org/CVERecord?id=CVE-2023-34462 Référence CVE CVE-2023-35116 https://www.cve.org/CVERecord?id=CVE-2023-35116 Référence CVE CVE-2023-3635 https://www.cve.org/CVERecord?id=CVE-2023-3635 Référence CVE CVE-2023-45853 https://www.cve.org/CVERecord?id=CVE-2023

Official advisory
CERT-FR · French · CERTFR-2025-AVI-0214Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2022-24302 Référence CVE CVE-2022-25857 https://www.cve.org/CVERecord?id=CVE-2022-25857 Référence CVE CVE-2022-35737 https://www.cve.org/CVERecord?id=CVE-2022-35737 Référence CVE CVE-2022-38900 https://www.cve.org/CVERecord?id=CVE-2022-38900 Référence CVE CVE-2022-41854 https://www.cve.org/CVERecord?id=CVE-2022-41854 Référence CVE CVE-2022-45061 https://www.cve.org/CVERecord?id=CVE-2022-45061 Référence CVE CVE-2022-46175 https://www.cve.org/CVERecord?id=CVE-2022-46175 Référence CVE CVE-2022-4742 https://www.cve.org/CVERecord?id=CVE-2022-4742 Référence CVE CVE-2022-48560 https://www.cve.org/CVERecord?id=CVE-2022-48560 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-48565 https://www.cve.org/CVERecord?id=CVE-2022-48565 Référence CVE CVE-2022-48566 https://www.cve.org/CVERecord?id=CVE-2022-48566 Référence CVE CVE-2022-49043 https://www.cve.org/CVERecord?id=CVE-2022-49043 Référence CVE CVE-2023-24329 https://www.cve.org/CVERecord?id=CVE-2023-24329 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-2023-27043 Référence CVE CVE-2023-2976 https://www.cve.org/CVERecord?id=CVE-2023-2976 Référence CVE CVE-2023-32573 https://www.cve.org/CVERecord?id=CVE-2023-32573 Référence CVE CVE-2023-32762 https://www.cve.org/CVERecord?id=CV

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0506Multiples vulnérabilités dans Juniper Secure Analytics

ord?id=CVE-2022-45061 Référence CVE CVE-2022-45869 https://www.cve.org/CVERecord?id=CVE-2022-45869 Référence CVE CVE-2022-45884 https://www.cve.org/CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2022-45934 https://www.cve.org/CVERecord?id=CVE-2022-45934 Référence CVE CVE-2022-46329 https://www.cve.org/CVERecord?id=CVE-2022-46329 Référence CVE CVE-2022-4744 https://www.cve.org/CVERecord?id=CVE-2022-4744 Référence CVE CVE-2022-48560 https://www.cve.org/CVERecord?id=CVE-2022-48560 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-48624 https://www.cve.org/CVERecord?id=CVE-2022-48624 Référence CVE CVE-2023-0458 https://www.cve.org/CVERecord?id=CVE-2023-0458 Référence CVE CVE-2023-0590 https://www.cve.org/CVERecord?id=CVE-2023-0590 Référence CVE CVE-2023-0597 https://www.cve.org/CVERecord?id=CVE-2023-0597 Référence CVE CVE-2023-1073 https://www.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0385Multiples vulnérabilités dans les produits IBM

ord?id=CVE-2022-41858 Référence CVE CVE-2022-42895 https://www.cve.org/CVERecord?id=CVE-2022-42895 Référence CVE CVE-2022-45688 https://www.cve.org/CVERecord?id=CVE-2022-45688 Référence CVE CVE-2022-45869 https://www.cve.org/CVERecord?id=CVE-2022-45869 Référence CVE CVE-2022-45884 https://www.cve.org/CVERecord?id=CVE-2022-45884 Référence CVE CVE-2022-45887 https://www.cve.org/CVERecord?id=CVE-2022-45887 Référence CVE CVE-2022-45919 https://www.cve.org/CVERecord?id=CVE-2022-45919 Référence CVE CVE-2022-4744 https://www.cve.org/CVERecord?id=CVE-2022-4744 Référence CVE CVE-2022-48560 https://www.cve.org/CVERecord?id=CVE-2022-48560 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-48624 https://www.cve.org/CVERecord?id=CVE-2022-48624 Référence CVE CVE-2023-0458 https://www.cve.org/CVERecord?id=CVE-2023-0458 Référence CVE CVE-2023-0590 https://www.cve.org/CVERecord?id=CVE-2023-0590 Référence CVE CVE-2023-0597 https://www.cve.org/CVERecord?id=CVE-2023-0597 Référence CVE CVE-2023-1073 https://www.cve.org/CVERecord?id=CVE-2023-1073 Référence CVE CVE-2023-1074 https://www.cve.org/CVERecord?id=CVE-2023-1074 Référence CVE CVE-2023-1075 https://www.cve.org/CVERecord?id=CVE-2023-1075 Référence CVE CVE-2023-1079 https://www.cve.org/CVERecord?id=CVE-2023-1079

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0305Multiples vulnérabilités dans les produits IBM

d?id=CVE-2022-34169 Référence CVE CVE-2022-41721 https://www.cve.org/CVERecord?id=CVE-2022-41721 Référence CVE CVE-2022-41723 https://www.cve.org/CVERecord?id=CVE-2022-41723 Référence CVE CVE-2022-42920 https://www.cve.org/CVERecord?id=CVE-2022-42920 Référence CVE CVE-2022-45061 https://www.cve.org/CVERecord?id=CVE-2022-45061 Référence CVE CVE-2022-46329 https://www.cve.org/CVERecord?id=CVE-2022-46329 Référence CVE CVE-2022-46363 https://www.cve.org/CVERecord?id=CVE-2022-46363 Référence CVE CVE-2022-46364 https://www.cve.org/CVERecord?id=CVE-2022-46364 Référence CVE CVE-2022-48560 https://www.cve.org/CVERecord?id=CVE-2022-48560 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-1786 https://www.cve.org/CVERecord?id=CVE-2023-1786 Référence CVE CVE-2023-20569 https://www.cve.org/CVERecord?id=CVE-2023-20569 Référence CVE CVE-2023-22067 https://www.cve.org/CVERecord?id=CVE-2023-22067 Référence CVE CVE-2023-22081 https://www.cve.org/CVERecord?id=CVE-2023-22081 Référence CVE CVE-2023-26159 https://www.cve.org/CVERecord?id=CVE-2023-26159 Référence CVE CVE-2023-26604 https://www.cve.org/CVERecord?id=CVE-2023-26604 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-

Official advisory
CERT-FR · French · CERTFR-2024-AVI-0262Multiples vulnérabilités dans les produits IBM

ecord?id=CVE-2021-28957 Référence CVE CVE-2021-43818 https://www.cve.org/CVERecord?id=CVE-2021-43818 Référence CVE CVE-2022-2127 https://www.cve.org/CVERecord?id=CVE-2022-2127 Référence CVE CVE-2022-25647 https://www.cve.org/CVERecord?id=CVE-2022-25647 Référence CVE CVE-2022-26377 https://www.cve.org/CVERecord?id=CVE-2022-26377 Référence CVE CVE-2022-36760 https://www.cve.org/CVERecord?id=CVE-2022-36760 Référence CVE CVE-2022-40303 https://www.cve.org/CVERecord?id=CVE-2022-40303 Référence CVE CVE-2022-40304 https://www.cve.org/CVERecord?id=CVE-2022-40304 Référence CVE CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2022-4304 Référence CVE CVE-2022-48564 https://www.cve.org/CVERecord?id=CVE-2022-48564 Référence CVE CVE-2022-48565 https://www.cve.org/CVERecord?id=CVE-2022-48565 Référence CVE CVE-2023-0215 https://www.cve.org/CVERecord?id=CVE-2023-0215 Référence CVE CVE-2023-0286 https://www.cve.org/CVERecord?id=CVE-2023-0286 Référence CVE CVE-2023-23931 https://www.cve.org/CVERecord?id=CVE-2023-23931 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-2023-27043 Référence CVE CVE-2023-3446 https://www.cve.org/CVERecord?id=CVE-2023-3446 Référence CVE CVE-2023-34966 https://www.cve.org/CVERecord?id=CVE-2023-34966 Référence CVE CVE-2023-34967 https://www.cve.org/CVERecord?id=CVE-20

Official advisory
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
n/a
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 22 Aug 2023 · Last source change 3 Aug 2024, 15:17 UTC · CWE-400 · Uncontrolled Resource Consumption

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2022-51260
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceNIST NVD
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates →

No material field changes have been recorded since change tracking began. Routine source refreshes and cosmetic edits are intentionally excluded.

Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2022-48564 · cve.blacktree.nl