CVE-2024-12970: OS Command Injection in TUBITAK BILGEM's Pardus OS My Computer

3.9 CVSS

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.

Classification

CVE ID: CVE-2024-12970

CVSS Base Severity: LOW

CVSS Base Score: 3.9

Affected Products

Vendor: TUBITAK BILGEM

Product: Pardus OS My Computer

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.77% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://www.usom.gov.tr/bildirim/tr-24-1900

Timeline