Impact
The vulnerability is a missing authorization check that allows an attacker to inject arbitrary arguments into TUBITAK BILGEM Software Technologies Research Institute’s pardus-software. This enables manipulation of the software’s behavior in unintended ways and is classified as CWE‑862.
Affected Systems
All deployments of pardus-software version 1.0.4 or earlier by TUBITAK BILGEM Software Technologies Research Institute. The issue is resolved in version 1.0.5 and later.
Risk and Exploitability
Based on the description, the likely attack vector is an interface that accepts arguments without proper access control—such as a command‑line option, script, or API call. The CVSS score of 8.8 indicates a high severity level. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation data.
OpenCVE Enrichment