Impact
An incomplete filter of disallowed input strings in the Amazon Agent Plugins for AWS databases‑on‑aws plugin prior to version 1.7.1 allows an unauthenticated actor to embed a database command value that is passed directly to the helper process. This results in arbitrary operating‑system command execution on the host in which the helper runs, compromising confidentiality, integrity, and availability of that system.
Affected Systems
The vulnerability affects all installations of the AWS databases‑on‑aws plugin older than version 1.7.1. These environments run the plugin on host machines that host or manage AWS database services. Any host that runs the helper process can be impacted if an attacker can inject a crafted database command value into the agent context.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score is not available, so the current exploitation probability is unknown, but the flaw permits unauthenticated remote execution through a craftable database command. The issue is not listed in CISA KEV, yet the potential impact of remote OS command execution warrants immediate action. Attackers can trigger the exploit by sending a crafted database command through the agent context, with no authentication required, making the attack path straightforward for any actor who can reach the agent interface.
OpenCVE Enrichment