Impact
A flaw exists in the Policy Gate Handler of invariant-systems-ai aiir version 1.7.0 and earlier, where an unknown function allows an attacker to manipulate input and cause the component to improperly verify cryptographic signatures. This results in a failure to detect forged or tampered policy data, potentially granting the attacker unauthorized actions within the system. The vulnerability is classified as a moderate severity, with a CVSS score of 6.9, and does not appear in the CISA KEV catalog.
Affected Systems
Products affected are invariant-systems-ai aiir up to and including version 1.7.0. The vendor has discontinued support for these releases and the repository is no longer publicly available.
Risk and Exploitability
The exploit is remote, allowing any network user to craft a request that bypasses signature verification. There is no publicly documented exploit code yet, and the EPSS score is not available. The CVSS score of 6.9 indicates that while the vulnerability can be used to gain unauthorized access or privileges, it requires successful remote exploitation and relies on a specific vulnerability in a cryptographic verification routine.
OpenCVE Enrichment