Impact
The vulnerability allows a physically present attacker to place an unsigned, empty igel.conf file on a device that runs IGEL OS 11 or 12. During the GRUB boot stage, the bootloader accepts the file and drops the user into an interactive GRUB prompt. From there the attacker can load the device’s own kernel with arbitrary command‑line arguments, which grants a root shell while keeping the TPM PCR values unchanged. This escalation gives the attacker full control over the machine and bypasses the device’s full‑desk encryption, enabling read, write, or modify operations on data that would normally be protected by secure boot and disk encryption.
Affected Systems
The vulnerability affects IGEL OS 12 versions prior to 12.9.0 (including 12.8.3 LTS) and IGEL OS 11 versions older than 11.11.150. It is limited to the GRUB boot process on IGEL thin‑client hardware running those OS builds and requires local physical access to the system to place the igel.conf file.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. While the exploit requires physical presence and local access, it is straightforward to carry out with knowledge of the device’s file system. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, meaning no large‑scale automated exploitation has been observed. Nevertheless, an attacker with physical access can gain complete root privileges and compromise confidentiality, integrity, and availability of system resources.
OpenCVE Enrichment