{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oigeligel_os12/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:igel:igel_os:12:*:*:*:*:*:*:*","cpe:2.3:o:igel:igel_os:11:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-82017"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IGEL OS 12 (\u003c 12.7.6)","IGEL OS 11 (\u003c 11.11.150)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["IGEL"],"content_html":"\u003cp\u003eCVE-2026-82017 is a boot-level vulnerability affecting IGEL OS 12 (versions prior to 12.7.6) and IGEL OS 11 (versions prior to 11.11.150). The flaw exists because the bootloader reads boot registry parameters from an unencrypted and unsigned configuration area. An attacker with physical access to the endpoint can modify these configuration files to inject arbitrary kernel command-line parameters. Because the attack targets the configuration data rather than the signed bootloader binary, the modifications do not trigger TPM PCR measurement failures, allowing the system to boot into a modified state with elevated privileges. This vulnerability is critical for organizations relying on IGEL OS endpoints for secure, locked-down kiosk or thin-client environments, as it effectively nullifies hardware-backed integrity protections.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains physical access to the targeted IGEL OS endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an interface to interact with the device storage (e.g., direct flash memory access or removable boot media manipulation).\u003c/li\u003e\n\u003cli\u003eAttacker identifies the unencrypted and unsigned configuration area used by the bootloader.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the boot registry parameter files within this area to include malicious kernel command-line parameters.\u003c/li\u003e\n\u003cli\u003eAttacker reboots or performs a hard reset on the target endpoint.\u003c/li\u003e\n\u003cli\u003eThe system bootloader executes, reading the tampered configuration parameters into the kernel startup sequence.\u003c/li\u003e\n\u003cli\u003eThe kernel initializes with the injected parameters, executing with boot environment privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistence or full control over the OS environment while bypassing established TPM security measurements.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the compromise of endpoint integrity, bypassing boot-time security controls such as TPM-based measured boot. This could facilitate the deployment of rootkits, exfiltration of stored credentials, or the total bypass of endpoint configuration locks in enterprise, healthcare, or financial kiosk environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all IGEL OS 12 endpoints to version 12.7.6 or later immediately.\u003c/li\u003e\n\u003cli\u003eUpgrade all IGEL OS 11 endpoints to version 11.11.150 or later immediately.\u003c/li\u003e\n\u003cli\u003eApply physical security controls to IGEL OS endpoints to prevent unauthorized access to storage media or boot interfaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T23:35:44Z","date_published":"2026-08-28T23:35:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-igel-boot-injection/","summary":"CVE-2026-82017 allows attackers with physical access to inject arbitrary kernel command-line parameters into IGEL OS boot configurations, resulting in privilege escalation while bypassing TPM measurements.","title":"Boot Registry Parameter Injection in IGEL OS","url":"https://feed.craftedsignal.io/briefs/2026-08-igel-boot-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:igel:igel_os:12:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}