Impact
The vulnerability is a missing authorization flaw that allows an attacker to elevate privileges and execute arbitrary code at the system level. Because the authorization check is absent, a user can gain root-level access and compromise confidentiality, integrity, and availability of the affected system. The weakness is identified as CWE-862.
Affected Systems
HAVELSAN Inc. Liman MYS, versions from 2.2.3 up to but not including 2.3.1.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity of this issue. EPSS is not available, so the exact exploitation likelihood is unknown, and the vulnerability is not listed in CISA's KEV catalog. The missing authorization check suggests that the vulnerability can be exploited without authentication, likely via remote or local access to the Liman MYS interface. An attacker with the ability to interact with the application can gain full root privileges, making this a high‑risk threat to affected deployments.
OpenCVE Enrichment