Impact
A vulnerability exists in the Bash Tool component of CowAgent up to version 2.1.7, allowing an attacker to trigger a denial of service through manipulations in the bash.py script. The flaw stems from missing validation in an unknown function and is classified as CWE‑404. Remote exploitation leads to the target becoming unresponsive, disrupting its availability and potentially affecting connected services.
Affected Systems
CowAgent, the BASH Tool component released zhayujie, with affected releases up to version 2.1.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. However, the publicly disclosed nature and remote attack vector imply that an attacker could initiate repeated execution attempts to exhaust resources and achieve denial of service.
OpenCVE Enrichment