Impact
A flaw was discovered in the run_openlane/view_waveform functionality of NellyW8 MCP4EDA 1.0.0, where manipulating either the design_name or vcd_file arguments allows an attacker with local access to inject arbitrary shell commands. The vulnerability falls under CWE-74 (Command Injection) and CWE-77 (Path Manipulation), potentially compromising the confidentiality, integrity, and availability of the host system for the attacking user. The CVSS score of 4.8 indicates a moderate severity level for this type of local code execution.
Affected Systems
The vulnerability affects the NellyW8 MCP4EDA product version 1.0.0, specifically the run_openlane/view_waveform component. Users running this version on any operating system with local user privileges may be impacted.
Risk and Exploitability
The attack vector is local, requiring the attacker to have foothold to execute the vulnerable command. No externally exploitable exposure is reported, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, which suggests limited publicly observed exploitation. However, because local users can issue the affected arguments, the risk remains for compromise of the local environment if this component is used by privileged processes.
OpenCVE Enrichment