Impact
OS command injection in the Cosminexus Component Container allows an attacker to inject and execute arbitrary OS commands. If the container processes untrusted input, the attacker can gain full control over the host system, compromising confidentiality, integrity, and availability. The vulnerability is classified as CWE-78.
Affected Systems
Hitachi Cosminexus Component Container is affected. The following version ranges are vulnerable: 11‑70‑01 through before 11‑70‑03, 11‑60 before 11‑60‑03, 11‑50 through 11‑50‑03, 11‑40 through 11‑40‑03, 11‑30 through 11‑30‑08, 11‑20 before 11‑20‑10, 11‑10 through 11‑10‑11, 11‑00 before 11‑00‑13, 09‑87 before 09‑87‑10, 09‑80 before 09‑80‑05, 09‑70 before 09‑70‑28, 09‑50 through 09‑50‑22, and 09‑00 through 09‑00‑18.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is severe. The EPSS score is not available, but the absence of a KEV listing does not reduce the risk because the high CVSS indicates potential for widespread exploitation. The attack vector is likely network‑based; a malicious actor can send crafted payloads to the container if it is exposed to an untrusted network. Exploitation requires local or network access to the component and may lead to complete system compromise.
OpenCVE Enrichment