CVE-2026-47192: CWE-347: Improper Verification of Cryptographic Signature in siemens kas
CVE-2026-47192 is a low-severity vulnerability in the Siemens kas tool versions 4.8 up to but not including 5.3. The flaw involves improper verification of cryptographic signatures, where kas processes repository configurations before validating their signatures. Under specific conditions involving repository control by an attacker and certain configuration settings, an attacker could replace a referenced repository with a malicious one. Patches addressing this issue were released in kas version 5.3. A recommended workaround is to pin the expected signature key via its fingerprint when storing it as a file in a repository.
AI Analysis
Technical Summary
The kas tool for bitbake-based projects, starting from version 4.8 and prior to 5.3, improperly verifies cryptographic signatures by processing repository configurations before signature validation. This can allow an attacker who controls a referenced repository and meets several specific conditions—such as the victim's kas configuration including a file from the attacker-controlled repository, referencing repository state by tag without commit ID, storing the key as a file without specifying a fingerprint, and not setting the _source_dir key—to replace the original repository with a malicious one. No other exploitation methods are currently identified. The vulnerability is addressed in kas version 5.3, and pinning the signature key by fingerprint is advised as a workaround.
Potential Impact
An attacker with control over a repository referenced by a victim's kas configuration could replace the original repository with a malicious one under very specific conditions. This could lead to the victim unknowingly processing attacker-controlled configuration files. The impact is limited by the complexity of required conditions and the low CVSS score (2.1), indicating low severity.
Mitigation Recommendations
A fix is available in kas version 5.3. Users should upgrade to version 5.3 or later to remediate this vulnerability. As a workaround, users can pin the expected signature key by its fingerprint even when the key is stored as a file in a repository. This prevents the attacker from substituting the key used for signature validation. No other mitigations are specified.
CVE-2026-47192: CWE-347: Improper Verification of Cryptographic Signature in siemens kas
Description
CVE-2026-47192 is a low-severity vulnerability in the Siemens kas tool versions 4.8 up to but not including 5.3. The flaw involves improper verification of cryptographic signatures, where kas processes repository configurations before validating their signatures. Under specific conditions involving repository control by an attacker and certain configuration settings, an attacker could replace a referenced repository with a malicious one. Patches addressing this issue were released in kas version 5.3. A recommended workaround is to pin the expected signature key via its fingerprint when storing it as a file in a repository.
CVSS v4.0
Score 2.1low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The kas tool for bitbake-based projects, starting from version 4.8 and prior to 5.3, improperly verifies cryptographic signatures by processing repository configurations before signature validation. This can allow an attacker who controls a referenced repository and meets several specific conditions—such as the victim's kas configuration including a file from the attacker-controlled repository, referencing repository state by tag without commit ID, storing the key as a file without specifying a fingerprint, and not setting the _source_dir key—to replace the original repository with a malicious one. No other exploitation methods are currently identified. The vulnerability is addressed in kas version 5.3, and pinning the signature key by fingerprint is advised as a workaround.
Potential Impact
An attacker with control over a repository referenced by a victim's kas configuration could replace the original repository with a malicious one under very specific conditions. This could lead to the victim unknowingly processing attacker-controlled configuration files. The impact is limited by the complexity of required conditions and the low CVSS score (2.1), indicating low severity.
Mitigation Recommendations
A fix is available in kas version 5.3. Users should upgrade to version 5.3 or later to remediate this vulnerability. As a workaround, users can pin the expected signature key by its fingerprint even when the key is stored as a file in a repository. This prevents the attacker from substituting the key used for signature validation. No other mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T22:07:37.435Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7f4ccfbf8831d53972218f
Added to database: 08/14/2026, 17:13:51 UTC
Last enriched: 08/14/2026, 17:31:19 UTC
Last updated: 08/14/2026, 17:31:19 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.