Description
Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data.

This issue affects Liman MYS: before release.Master.1107.
Published: 2026-07-07
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in HAVELSAN Inc.'s Liman MYS arises from improper verification of cryptographic signatures. An attacker can forge the source of data by presenting a synthetic signature that is incorrectly validated, thereby bypassing the system’s authentication checks. This weakness is classified as CWE-347, which involves insecure cryptographic validation.

Affected Systems

HAVELSAN Inc.'s Liman MYS, all releases before release.Master.1107.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of <1% suggests a low potential for exploitation. The vulnerability is not listed in the CISA KEV catalog, which indicates no confirmed exploitation yet. Based on the description inferred that an attacker could send forged data over a network that includes an invalid cryptographic signature; because the system does not verify it properly, the system will accept it. Thus the likely attack vector is remote via network communications.

Generated by OpenCVE AI on July 26, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Liman MYS to release.Master.1107 or a newer version where signature verification has been corrected.
  • Ensure that cryptographic signature validation uses a secure algorithm and that only trusted keys are accepted; implement strict key management policies.
  • Monitor logs for unexpected or forged signed data to detect potential abuse.

Generated by OpenCVE AI on July 26, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan liman Mys
Vendors & Products Havelsan
Havelsan liman Mys

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107.
Title Authentication Bypass in HAVELSAN's Open Source Project Liman MYS
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Havelsan Liman Mys
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:23:08.844Z

Reserved: 2026-06-05T09:05:34.611Z

Link: CVE-2026-11348

cve-icon Vulnrichment

Updated: 2026-07-07T13:23:00.547Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature