← Back to CVE List
Vulnerability Intelligence Report
IGEL OS Use of a Key Past its Expiration Date Vulnerability

CVE-2025-47827

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
4.6
MEDIUM
Exploitability:1.0
Impact Score:3.6
EPSS Probability:3.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-347 ↗CWE-347 Improper Verification of Cryptographic Signature

Affected Products & Versions

Vendor Product Affected Versions
igel igel_os all
microsoft windows_10_1507 all
microsoft windows_10_1607 all
microsoft windows_10_1809 all
microsoft windows_10_21h2 all
microsoft windows_10_22h2 all
microsoft windows_11_22h2 all
microsoft windows_11_23h2 all
microsoft windows_11_24h2 all
microsoft windows_11_25h2 all
microsoft windows_server_2012 r2
microsoft windows_server_2016 all
microsoft windows_server_2019 all
microsoft windows_server_2022 all
microsoft windows_server_2022_23h2 all
microsoft windows_server_2025 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
3.528%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-05-11T00:00:00
Published2025-06-05T00:00:00
Last Updated2026-02-26T17:51:07

LINK COPIED TO CLIPBOARD