Skip to content
COOEY

EXPOSURES › CVE-2025-47827

CVE-2025-47827

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-10-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-47827 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

IGEL OS Secure Boot bypass due to expired key verification

IGEL OS, a critical component in DIB networks, suffered a vulnerability that allowed an attacker to bypass Secure Boot, mounting a crafted root filesystem from an unverified SquashFS image. This exposed the system to potential compromise, highlighting the importance of timely software updates.

Shame score — Critical system bypass due to expired key verification, posing a high risk to DIB networks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.