CyberRota Analysis
AI-GeneratedIGEL OS versions prior to 12.7.6 and 11.11.150 are vulnerable to a boot registry parameter injection flaw that enables attackers with physical access to execute arbitrary Linux loader parameters. This vulnerability allows for the injection of malicious kernel command line parameters, granting elevated privileges during the boot process without triggering security mechanisms. Organizations using affected IGEL OS versions should prioritize remediation to mitigate potential unauthorized access and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.