← לוח פגיעויות

CVE-2025-47827

בינונית 4.6 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
IGEL OS Use of a Key Past its Expiration Date Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

מדדים

CVSS 3.1
4.6 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
4% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-347

מוצרים מושפעים

igel: igel os; microsoft: windows 10 1507; microsoft: windows 10 1607; microsoft: windows 10 1809; microsoft: windows 10 21h2; microsoft: windows 10 22h2; microsoft: windows 11 22h2; microsoft: windows 11 23h2; microsoft: windows 11 24h2; microsoft: windows 11 25h2; microsoft: windows server 2012; microsoft: windows server 2016; microsoft: windows server 2019; microsoft: windows server 2022; microsoft: windows server 2022 23h2

קישורים