Impact
The vulnerability exists in the password reset functionality of Squirro Cognitive Search versions prior to 3.14.2. A crafted payload to the password reset endpoint can enable a remote attacker to execute arbitrary code on the host, potentially leading to full system compromise and data exfiltration. The issue originates from insufficient input validation, exposing the system to command or code injection attacks.
Affected Systems
Squirro Cognitive Search software, specifically any deployment running a version earlier than 3.14.2.
Risk and Exploitability
The CVSS score is 9.8, indicating a critical severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is low. It is inferred that the attack vector is likely remote over HTTP/HTTPS, and that the password reset request does not require authentication.
OpenCVE Enrichment