Impact
The Heimdall Data Database Proxy flaw lies in the generateFileContent routine, which fails to neutralise CRLF characters. An attacker who can authenticate can inject crafted CRLF sequences that are interpreted as executable commands. The flaw can lead to arbitrary code running under root, giving an attacker full control over the target system.
Affected Systems
Affected installations are any Heimdall Data Database Proxy that still contains the vulnerable generateFileContent routine. No specific product versions were listed, so all current and prior releases might be at risk. The vulnerability requires authenticated access, meaning internal users or compromised credentials can provoke the exploit.
Risk and Exploitability
The CVSS score of 7.2 and an EPSS of 1% signal a high‑severity flaw that is unlikely to be widely exploited yet but can cause severe damage. Although it does not appear in CISA’s KEV catalog, attackers with valid credentials could craft malicious CRLF payloads and trigger remote code execution. The need for authentication lowers the attack surface but still represents a critical risk to privileged accounts.
OpenCVE Enrichment