Impact
OS Command Injection allows unauthenticated remote attackers to cause a vulnerable local service interface to execute arbitrary commands by visiting a malicious web page. The consequence is execution of arbitrary OS commands on the victim’s system, compromising confidentiality, integrity, and availability. This flaw corresponds to CWE-78.
Affected Systems
The affected product is Changing’s CGServiSign. Versions prior to NHIServisign 1.0.26.0625 on Linux are vulnerable. No other versions are mentioned in the advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and an EPSS score of 2% indicates a low but non-zero exploitation probability, while the lack of KEV inclusion suggests no known large-scale exploitation yet. The vulnerability is exploitable by anyone who can lure a user to a crafted web page that interacts with the local service interface, thus making it reachable over the network. The risk to systems where CGServiSign is installed is significant, as full system compromise is possible if no mitigations are applied.
OpenCVE Enrichment