Impact
Invocation of a process that exposes sensitive information results in OTP secrets appearing in the command-line arguments of eta‑otp‑lock. This leads to information disclosure.
Affected Systems
The affected product is TÜBİTAK BİLGEM Software Technologies Research Institute’s eta‑otp‑lock. Versions prior to 1.0.4 are vulnerable.
Risk and Exploitability
The CVSS score of 5 indicates a moderate severity. EPSS data is not available and the issue is not listed in CISA KEV, suggesting limited known exploitation. The likely attack vector is local or privileged system users who can view the process list; this is inferred from the nature of the vulnerability. Overall risk is moderate but present for hosts exposing process arguments to non‑trusted users.
OpenCVE Enrichment