Impact
The vulnerability is an OS command injection flaw (CWE‑78) in TUBITAK BILGEM Software Technologies Research Institute’s Pardus Software that results from improper neutralization of special elements used in an OS command execute arbitrary operating‑system commands. Based on the description, it is inferred that such arbitrary command execution can compromise the confidentiality, integrity, and availability of the affected system.
Affected Systems
TUBITAK BILGEM Software Technologies Research Institute’s Pardus Software versions prior to 1.0.5.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector would involve an attacker providing crafted input that reaches the vulnerable component, which could be possible remotely or locally by an unprivileged user; the exact prerequisites are not explicitly stated in the description.
OpenCVE Enrichment