Status: UPDATED
| Advisory ID: CVE-2026-82017
Key Details
| CVE | CVE-2026-82017 |
| CVSS Score / Version | 7.6 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is physical; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | IGEL IGEL OS 12 and IGEL IGEL OS 11 |
| Classified as | CWE-345 (Insufficient Verification of Data Authenticity) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code. (NVD)
What to Do
Monitor IGEL's web page for any future patch releases.
References