Impact
Improper neutralization of argument delimiters in the command execution context allows an attacker to inject arbitrary arguments into the command line invoked by Pardus Pen. This flaw (CWE-88) can lead to the execution of unintended commands, potentially providing local code execution or privilege escalation for attackers with sufficient access to the application. The impact is limited to the scope of the user who can supply the argument payload, and the vulnerability does not directly expose sensitive data or allow remote exploitation.
Affected Systems
Affected products are TUBITAK BILGEM Software Technologies Research Institute’s Pardus Pen versions earlier than 4.2.1. The flaw is present in all builds before 4.2.1, and updating to 4.2.1 or later removes it.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, reflecting a limited effect and a low likelihood of widespread exploitation. EPSS is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known or actively exploited threat. Based on the description, the likely attack vector would be a local user or attacker with sufficient privileges to interact with Pardus Pen, with no remote exploitation path documented. The lack of active exploitation and a low CVSS level imply a low overall risk for unpatched systems, but unpatched installations should still be updated to avoid potential local exploitation.
OpenCVE Enrichment