Impact
A flaw in the fixedCommand method of PlatformUtils.java within the HummerRisk Cloud Compliance Scanning component allows an attacker to inject and execute arbitrary operating system commands. This command injection can compromise the confidentiality, integrity, and availability of the host system by enabling remote code execution. The vulnerability is categorized as CWE-74 and CWE-77.
Affected Systems
The issue affects all releases of the HummerRisk Cloud Compliance Scanning product up to and including version 1.5.0. Any installation that is running 1.5.0 or an older version is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, and the EPSS score of 12% indicates a moderate likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Attackers can exploit the flaw from a remote location without additional prerequisites, triggering command injection by manipulating the fixedCommand input. Successful exploitation would allow the attacker to execute arbitrary operating system commands on the host running the HummerRisk Cloud Compliance Scanning service.
OpenCVE Enrichment