Impact
PFU Limited’s Image Scanner Driver for Linux contains a link following vulnerability that permits local logged‑in users to overwrite arbitrary files. This flaw can be triggered by a special method supplied with the driver and is not limited to configuration files; any file on the system can be replaced, enabling attackers to modify binaries or other critical resources.
Affected Systems
The vulnerability affects the PFU Limited Image Scanner Driver for Linux for both the SP Series and the fi Series. No specific version information is listed, meaning all installed instances of the driver are potentially impacted.
Risk and Exploitability
The CVSS score of 5.2 places the flaw in a moderate risk range. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The exploit requires local access to a Linux system where the driver is installed; an attacker must be able to authenticate locally to leverage the vulnerable method. Once the method is executed, any file that the user has permission to overwrite can be altered, which may enable privilege escalation or lead to denial of service if critical system components are tampered with.
OpenCVE Enrichment