EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
- •High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0.1%CVSS: 7.8Exploit: None knownExposed services: Not assessed
An upstream fix is merged but not yet released — mitigate (WAF / firewall / segmentation) until the release ships, then apply it.
An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted database command value introduced in the agent context.
To remediate this issue, users should upgrade to databases-on-aws plugin version 1.7.1 or later and verify that the updated plugin is active in each environment where it is used.
CISA SSVCTrack at low or medium mission impact; Track* at high (mission-essential systems).
An upstream fix is merged but not yet in a tagged release. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines until it ships, then apply the release.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table