Impact
A vulnerability in Disig Web Signer allows an attacker to execute arbitrary code on the host system. The flaw is present in versions 2.0.3 through 2.5.3 and can be triggered by a remote attacker.
Affected Systems
Disig Web Signer versions 2.0.3 to 2.5.3 are affected. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. EPSS data is not available, so the exploitation probability is unknown, but the absence from the KEV catalog does not negate risk. The likely attack vector is a remote user submitting a crafted request to the Web Signer application, probably via its web UI or API endpoint. Successful exploitation could give the attacker a full shell on the system hosting the application.
OpenCVE Enrichment