Impact
The vulnerability is an OS command injection flaw in Palo Alto Networks Checkov by Prisma Cloud. A local user can supply input that is executed directly by the Checkov process, enabling arbitrary command execution, which could lead to unauthorized code execution, data exfiltration, or system compromise.
Affected Systems
Vendor: Palo Alto Networks. Product: Checkov by Prisma Cloud. Versions 3.2.0 through 3.2.501 are vulnerable. Version 3.2.502 and later contain the fix.
Risk and Exploitability
With a CVSS score of 1.1 the technical impact is assessed as low and no exploit data is currently available. The EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, indicating limited exploitation evidence. The CVE description indicates that a local user can execute arbitrary commands, so the likely attack vector is local access. While the risk is modest, the ability to run arbitrary commands makes the flaw potentially dangerous if the local user account is compromised or privileges are not strictly controlled.
OpenCVE Enrichment