EXPOSURES › CVE-2025-47827
CVE-2025-47827
HIGH ⌖ ON CISA KEV · EXPLOITEDIGEL OS Secure Boot bypass due to expired key verification
IGEL OS, a critical component in DIB networks, suffered a vulnerability that allowed an attacker to bypass Secure Boot, mounting a crafted root filesystem from an unverified SquashFS image. This exposed the system to potential compromise, highlighting the importance of timely software updates.
Shame score — Critical system bypass due to expired key verification, posing a high risk to DIB networks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.