CVE-2018-6791 is a command injection vulnerability in KDE Plasma Workspace before version 5.12.0, specifically affecting the soliduiserver/deviceserviceaction.cpp component. It allows arbitrary command execution when a VFAT thumb drive with specially crafted volume labels (containing backticks or dollar-parentheses) is plugged in and mounted via the device notifier. This vulnerability has a CVSS v3 score of 6.8 (Medium), indicating a physical attack vector with low complexity, requiring no user interaction, and leading to high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code, or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.12.0CPE matchmatch criteria | cpe:2.3:a:kde:plasma-workspace:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.