Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77q2-m9gq-g982

Опубликовано: 27 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

EPSS

Процентиль: 19%
0.00061
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 3 года назад

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

CVSS3: 6.7
nvd
почти 3 года назад

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

msrc
почти 3 года назад

CERT/CC: CVE-2022-34302 New Horizon Data Systems Inc Boot Loader Bypass

CVSS3: 6.8
fstec
почти 3 года назад

Уязвимость загрузчика New Horizon Data Systems операционных систем Windows, позволяющая нарушителю обойти существующие ограничения безопасности

oracle-oval
около 2 лет назад

ELSA-2023-2487: fwupd security and bug fix update (MODERATE)

EPSS

Процентиль: 19%
0.00061
Низкий

6.7 Medium

CVSS3