Impact
This vulnerability originates from the improper neutralization of argument delimiters in a command constructed by TUBITAK BILGEM Software Technologies Research Institute’s pardus-software. The flaw allows an attacker to inject additional arguments into the system command line, enabling arbitrary command execution with the privileges of the software process (CWE-88). The CVSS score of 8.8 reflects the potential for full compromise of confidentiality, integrity, or availability of affected systems.
Affected Systems
The flaw is present in pardus-software versions 1.0.4 and earlier. The issue was resolved in version 1.0.5 and later; therefore, any deployment running a version earlier than 1.0.5 is vulnerable.
Risk and Exploitability
The high‑severity CVSS score of 8.8 indicates a serious impact if exploited. Its EPSS score of < 1 % suggests a low probability of being targeted in the near term, and it is not listed in CISA’s KEV catalog. Attackers would need to supply crafted input that bypasses sanitisation and reaches the shell, allowing injected arguments to execute with the software’s process privileges. Because the likely attack vector involves local or remote code submission that is concatenated into a system command line, mitigating improper argument neutralisation is essential.
OpenCVE Enrichment