Impact
The vulnerability is a missing authorization flaw in Pardus Update that permits users who can invoke privileged update functions to elevate their privileges. Classified as CWE‑862, the flaw indicates that the software does not enforce proper access controls, allowing an attacker to gain elevated permissions when the update service is triggered.
Affected Systems
The affected product is Pardus Update from TUBITAK BILGEM Software Technologies Research Institute. All releases prior to version 0.6.6, including 0.6.3 and earlier, contain the vulnerability.
Risk and Exploitability
The CVSS base score of 7.8 shows a high level of risk. The EPSS score of < 1% indicates only a very low probability of exploitation today, and the vulnerability does not appear in CISA's KEV catalog. The CVE description does not specify whether the flaw is exploitable locally or remotely, so the exact attack vector remains unknown. An attacker would need the ability to trigger the privileged update functions to exploit the missing authorization check.
OpenCVE Enrichment