Impact
The vulnerability is a stack buffer overflow that can be triggered by executing a malicious or compromised NASL vulnerability test (VT) on Greenbone OS and the openvas‑scanner component. When successfully triggered, it allows the attacker to execute arbitrary code and gain full system access, effectively compromising confidentiality, integrity, and availability. This weakness is identified as CWE‑787, illustrating improper handling of buffer sizes.
Affected Systems
The affected systems are Greenbone OS and the openvas‑scanner product from Greenbone. All versions of these products that are still running the vulnerable code are at risk, unless a vendor patch has been applied. The product CPE strings confirm that the vulnerability spans the main line of Greenbone’s security tools.
Risk and Exploitability
The CVSS score of 8.7 signals high severity, while the EPSS score is currently unavailable, making it unclear how frequently this flaw is being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must be able to run a malicious NASL VT with user privileges on the target machine, indicating that the attack vector requires an authenticated user or a compromised account. If user privileges are tightly controlled, the risk is reduced; however, in environments where credentials are shared or elevated access is common, the potential for exploitation remains significant.
OpenCVE Enrichment