Impact
The DigiDoc4 client contains a Path Traversal flaw that enables an attacker to overwrite files outside the intended directory. This issue can lead to the replacement of critical system or application files, potentially allowing further exploitation or denial of service. The weakness is identified as CWE-22 and is rated with a CVSS score of 8.4, indicating a high severity impact if exploited.
Affected Systems
The vulnerability is present in DigiDoc4 versions 4.0.0 through 4.10.x, all releases before 4.11.0, issued by the Estonian Information System Authority (RIA). Only these specific version ranges are affected; newer versions are presumed fixed.
Risk and Exploitability
With an unavailable EPSS score, the likelihood of exploitation is unclear, yet the high CVSS suggests significant risk. The CVE is not listed in the CISA KEV catalog. The path traversal flaw would likely be exploited by a local user or a malicious document that forces the client to write arbitrary data to a chosen location. No public exploit code is cited, but the high severity warrants immediate attention.
OpenCVE Enrichment