Impact
A flaw in Thales CERT Suspicious application versions up to and including 1.3.4 permits a remote, unauthenticated attacker to execute arbitrary code and overwrite any writable application files—including Python modules and configuration files—within the Django container. The consequences are a persistent denial of service, compromised application secrets or integration points, and the ability to achieve root‑level execution inside the container. The vulnerability stems from file path traversal, relative path injection, and code injection weaknesses (CWE‑22, CWE‑73, CWE‑94).
Affected Systems
All deployments of the Thales CERT Suspicious application with version numbers below 1.3.5 are affected. The application runs as a Django web service within a containerized environment and requires an upgrade to the patched release v1.3.5 to remove the flaw.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, while the EPSS score of less than 1% shows the likelihood of observed exploitation is currently low. The vulnerability is listed as not included in CISA’s KEV catalog. Based on the description, it is inferred that attackers can exploit the weakness from outside the network without authentication by crafting malicious requests that trigger arbitrary file writes or code execution inside the container.
OpenCVE Enrichment