Impact
The vulnerability in HAVELSAN Inc.'s Liman MYS arises from improper verification of cryptographic signatures. An attacker can forge the source of data by presenting a synthetic signature that is incorrectly validated, thereby bypassing the system’s authentication checks. This weakness is classified as CWE-347, which involves insecure cryptographic validation.
Affected Systems
HAVELSAN Inc.'s Liman MYS, all releases before release.Master.1107.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of <1% suggests a low potential for exploitation. The vulnerability is not listed in the CISA KEV catalog, which indicates no confirmed exploitation yet. Based on the description inferred that an attacker could send forged data over a network that includes an invalid cryptographic signature; because the system does not verify it properly, the system will accept it. Thus the likely attack vector is remote via network communications.
OpenCVE Enrichment