Impact
The vulnerability resides in the fixedCommand function of the PlatformUtils utility within the HummerRisk Cloud Compliance Scanning component. Malformed input can cause the operating system to execute arbitrary commands, compromising confidentiality, integrity, and availability. The flaw corresponds to classic command injection weaknesses, classified under CWE-74 and CWE-77.
Affected Systems
The flaw impacts HummerRisk Cloud Compliance Scanning, version 1.5.0 and earlier, as identified by the CPE hummerrisk:hummerrisk. All deployments using 1.5.0 or older are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while an EPSS of < 1% suggests a low probability of exploitation at present. Nevertheless, an exploit has already been published and the attack can be performed remotely, as stated in the description. No authentication is required beyond the ability to invoke the vulnerable API. The vulnerability is not listed in the KEV catalog.
OpenCVE Enrichment