Impact
The vulnerability stems from incorrect permission assignments to the DNS configuration component in TUBITAK BILGEM’s Pardus‑Parental‑Control, allowing an attacker to modify critical DNS resources. This flaw permits the injection of spoofed DNS responses, which can redirect traffic, facilitate phishing, or cause denial of service. Based on the description, it is inferred that an attacker capable of altering DNS records could manipulate domain resolution to their advantage.
Affected Systems
Pardus‑Parental‑Control versions 0.5.1 and earlier, and any build before 0.7.0, distributed by the TUBITAK BILGEM Software Technologies Research Institute, contain the vulnerable DNS configuration code and are therefore affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred to require the ability to modify DNS configuration, either via local privilege or by exploiting a remote interface that grants such rights.
OpenCVE Enrichment