OS Command Injection in TUBITAK BILGEM's Pardus OS My Computer
Summary
| CVE | CVE-2024-12970 |
|---|---|
| State | PUBLISHED |
| Assigner | TR-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-01-06 12:15:06 UTC |
| Updated | 2026-06-01 13:16:25 UTC |
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: before 0.7.2. |
Risk And Classification
Primary CVSS: v3.1 3.9 LOW from [email protected]
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
EPSS: 0.026670000 probability, percentile 0.860790000 (date 2026-06-03)
Problem Types: CWE-78 | CWE-78 CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.9 | LOW | CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
| 3.1 | CNA | CVSS | 3.9 | LOW | CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TUBITAK BILGEM | Pardus OS My Computer | affected 0.7.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-1900 | [email protected] | siberguvenlik.gov.tr | |
| www.usom.gov.tr/bildirim/tr-24-1900 | [email protected] | www.usom.gov.tr | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Osman Can VURAL (en)
There are currently no legacy QID mappings associated with this CVE.