Impact
The vulnerability is an OS command injection in Pardus Boot Repair. The application fails to neutralize special elements used in an OS command, allowing an attacker to inject arbitrary shell commands. If an attacker can trigger the affected functionality, they could execute commands with the privileges of the process, potentially gaining full system control. The weakness is classified as CWE-78.
Affected Systems
TUBITAK BILGEM Software Technologies Research Institute offers Pardus Boot Repair. Versions prior to 1.0.8 are affected. Upgrading to version 1.0.8 or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score is unavailable. The vulnerability is not currently listed in the CISA KEV catalog. Because the tool operates with elevated privileges to modify boot configuration, the likely attack vector is a local user or an attacker with access to the repair utility. An exploit could lead to arbitrary code execution, compromising confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment