Impact
The flaw is located in the reset_storage function of hunvreus devpush, where exception conditions are not correctly checked or handled. This can cause the storage layer to be reset unexpectedly, leading to loss of data or interruption of service. The description notes a high complexity level for the attack, but cites that exploitation is known to be difficult, suggesting that while the defect exists, it is not trivial for an attacker to trigger it.
Affected Systems
The vulnerability affects all releases of the hunvreus devpush project up to and including version 0.4.6. Users running devpush in that version range should be alerted. Specific details on later patch releases are not provided here.
Risk and Exploitability
The CVSS score of 2.1 indicates low overall severity. The EPSS score of less than 1% reflects a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly described in the data; based on context it is inferred that successful exploitation would likely require access to the service environment or privileged orchestration of the reset_storage task. Because the exploitation is known to be difficult, the risk to an organization is considered low, pending additional mitigations.
OpenCVE Enrichment