CVE-2023-6656
low-risk
Published 2023-12-10
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. It has been rated as critical. Affected by this issue is some unknown functionality of the file DFLIMG/DFLJPG.py. The manipulation leads to deserialization. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of this vulnerability is VDB-247364. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Do I need to act?
-
0.09% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.0/10
Medium
NETWORK
/ HIGH complexity
Affected Products (1)
Deepfacelab
Affected Vendors
References (6)
Broken Link
https://github.com/bayuncao/vul-cve-1
Permissions Required
https://vuldb.com/?ctiid.247364
Third Party Advisory
https://vuldb.com/?id.247364
Broken Link
https://github.com/bayuncao/vul-cve-1
Permissions Required
https://vuldb.com/?ctiid.247364
Third Party Advisory
https://vuldb.com/?id.247364
21
/ 100
low-risk
Severity
16/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal