Impact
The IXON VPN Client before version 1.4.7 fails to neutralize CRLF sequences in configuration data that is later consumed by a privileged subprocess. An attacker can supply configuration changes without authenticating the source, leading to injected directives that execute arbitrary commands as root or SYSTEM. The exploit does not alter the visual behavior of the VPN connection, so the user sees no apparent change.
Affected Systems
The affected product is IXON VPN Client. Any installation of IXON VPN Client older than version 1.4.7 is vulnerable. The client has been configured to reject connections from versions below 1.4.7, preventing the exploit chain from completing, but unpatched clients remain at risk.
Risk and Exploitability
With a CVSS score of 9.4 the vulnerability is high severity. No EPSS score is available and it is not listed in the CISA KEV catalog, but the attack would require delivery of a crafted configuration change to the client, which is plausible in environments where the client can be remotely accessed or where a local attacker can modify configuration files. The privileged subprocess runs with system-level rights, making the impact of successful exploitation catastrophic.
OpenCVE Enrichment