Impact
The PFU Image Scanner Driver for Linux contains an OS command injection flaw that allows an authenticated local user to execute arbitrary commands on the host. This vulnerability can lead to complete compromise of confidentiality, integrity, and availability of the affected system, as the attacker could run any shell command with the privileges of the user who logged in.
Affected Systems
The vulnerability affects PFU Limited Image Scanner Driver for Linux, specifically the SP Series and fi Series drivers. No specific version numbers are provided in the available data, so all deployments of these drivers are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires the attacker to be authenticated on the Linux system, which suggests that the exploitation vector is a local attacker with login capability. While the risk is moderate, any user with access to the affected driver could potentially elevate privileges or compromise the system if the vulnerability is actively exploited.
OpenCVE Enrichment