Impact
An attacker can exploit improper neutralization of special elements used in enabling them to execute arbitrary commands on the affected system. The vulnerability corresponds to CWE‑78 and, if leveraged, could compromise confidentiality, integrity, and availability by allowing the attacker to run any system command.
Affected Systems
The vulnerability affects the TUBITAK BILGEM Software Technologies Research Institute's pardus‑update utility, specifically versions 0.6.6 up to, but not including, 0.7.0. This product is used to implement offline system updates on Pardus distributions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk. The EPSS score of less than 1 % suggests that, as exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is local or an attacker that can supply without proper sanitization.
OpenCVE Enrichment