Home
HIGH: 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
8.4.4
affected
Default status
unaffected
3.0.2
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
0.0.0 (semver)
affected
Default status
unaffected
8.4.4
affected
Default status
unaffected
3.0.2
affected
Description
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Problem types
CWE-1287 Improper Validation of Specified Type of Input
Product status
0.0.0 (semver)
0.0.0 (semver)
8.4.4
3.0.2
0.0.0 (semver)
0.0.0 (semver)
8.4.4
3.0.2
Credits
Moritz Abrell from SySS GmbH
Christian Zäske from SySS GmbH
References
www.certvde.com/en/advisories/VDE-2026-054/