Impact
A flaw in Northern.tech CFEngine Enterprise and Community allows an attacker to inject arbitrary shell commands. This violation of the principle of correct input handling enables the execution of unwanted code, leading to compromise of confidentiality, integrity, and availability of the affected system. The weakness is identified as a typical command injection vulnerability (CWE-78).
Affected Systems
The vulnerability is present in CFEngine Enterprise and Community versions prior to 3.21.8, 3.24.3, and 3.27.0. Only these earlier releases are affected; newer releases release the fix. The product is distributed by Northern.tech and widely used for configuration management and automation.
Risk and Exploitability
There is no EPSS score and the vulnerability is not listed in the CISA KEV catalog, indicating limited public exploitation data. The available description indicates that an attacker can inject arbitrary commands, but the exact attack vector is not specified in the advisory; it is inferred that a remote or local attacker with sufficient CFEngine access could exploit the flaw. Because the flaw directly executes commands, the risk is high. MITRE CVSS has not been provided, but the impact is severe and the potential for full compromise exists if the attacker can trigger the injection.
OpenCVE Enrichment