Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xg9-v43g-xgcj

Опубликовано: 26 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

EPSS

Процентиль: 2%
0.00014
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
больше 1 года назад

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

CVSS3: 6.4
nvd
больше 1 года назад

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

CVSS3: 8.2
fstec
больше 1 года назад

Уязвимость микропрограммного обеспечения UEFI (BIOS), связанная с возможностью использования жёстко закодированных ключей платформы, позволяющая нарушителю выполнить произвольный код до загрузки операционной системы

EPSS

Процентиль: 2%
0.00014
Низкий

6.4 Medium

CVSS3