Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xg9-v43g-xgcj

Опубликовано: 26 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

EPSS

Процентиль: 19%
0.00274
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
около 2 лет назад

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

CVSS3: 6.4
nvd
около 2 лет назад

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

CVSS3: 8.2
fstec
около 2 лет назад

Уязвимость микропрограммного обеспечения UEFI (BIOS), связанная с возможностью использования жёстко закодированных ключей платформы, позволяющая нарушителю выполнить произвольный код до загрузки операционной системы

EPSS

Процентиль: 19%
0.00274
Низкий

6.4 Medium

CVSS3