Impact
A command argument injection flaw in Hitachi Cosminexus Component Container allows an attacker to supply crafted arguments that are directly passed to the operating system shell, enabling execution of arbitrary commands. This weakness, identified as CWE-88, can compromise confidentiality, integrity, and availability by allowing an attacker to run any code with the privileges of the container process. The high CVSS score of 9.8 reflects the criticality of this ability.
Affected Systems
Affected systems are Hitachi Cosminexus Component Container versions ranging from 09-00 through 09-00-18, 09-50 through 09-50-22, 09-70 before 09-70-28, 09-80 through 09-80-04, 09-87 before 09-87-10, 11-00 through 11-00-12, 11-10 through 11-10-11, 11-20 before 11-20-10, 11-30 through 11-30-08, 11-40 through 11-40-03, 11-50 through 11-50-03, 11-60 before 11-60-03, and 11-70-01 before 11-70-03.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8 and is not listed in the CISA KEV catalog, but the lack of an EPSS value means the current exploitation probability is unknown. The likely attack vector is via network or application interfaces that accept unfiltered command arguments, and an attacker with sufficient network access can exploit the injection to run arbitrary code inside the container environment.
OpenCVE Enrichment