Impact
An unmanaged input leads to OS command injection in Pardus Boot Repair, allowing an attacker to execute arbitrary shell commands. The vulnerability can compromise confidentiality, integrity, and availability of the affected system, potentially giving an attacker full control if executed with elevated privileges.
Affected Systems
The flaw exists in TÜBİTAK BİLGEM Software Technologies Research Institute's Pardus Boot Repair utility, specifically versions 1.0.7 and any earlier releases prior to 1.0.8.
Risk and Exploitability
The CVSS score of 7.8 indicates substantial risk. No EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. The attack vector is not explicitly disclosed in the description; the likely scenario requires local or privileged access to run the boot repair tool, or remote exposure if the utility is otherwise accessible. Because the attack path is uncertain, it is prudent to assume the vulnerability could be leveraged by a malicious actor with user or higher privileges within the system.
OpenCVE Enrichment