claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2025-47827-igel-igel-os.log

CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability

2025-10-14 • CISA Known Exploited Vulnerability


[event] IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

> AFFECTED SOFTWARE

Field Value
Vendor IGEL
Product IGEL OS
CWE CWE-324
CVE ID CVE-2025-47827
Date Added 2025-10-14
Due Date 2025-11-04
Ransomware Campaign Unknown

> MITIGATION

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due Date: 2025-11-04

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:07 UTC