Impact
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 permit an attacker with physical access to write arbitrary kernel command line parameters to an unsigned, unencrypted configuration area. The unsigned data is read by the signed bootloader, allowing the injected parameters to run with boot‑level privileges without triggering TPM PCR measurement failures. Therefore, an attacker can execute arbitrary code during system startup with full system privileges.
Affected Systems
Affected systems include IGEL OS 11 versions before 11.11.150 and IGEL OS 12 versions before 12.7.6. The vulnerability is present in both the 11 and 12 product lines of IGEL OS.
Risk and Exploitability
According to the CVSS score of 8.6, this flaw is classified as high severity. EPSS data is not available, so the current exploitation probability is unclear, but the lack of KEV listing indicates no known mass exploitation yet. Exploitation requires physical access and the ability to write to the unsigned configuration cache. Attackers can use the provided script from the cited research or similar tooling to inject malicious parameters. The attack vector is physical and local, and the impact is achieved at boot time, before the operating system operational checks.
OpenCVE Enrichment