Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j33-663j-fx7f

Опубликовано: 27 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

EPSS

Процентиль: 17%
0.00053
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
redhat
почти 3 года назад

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

CVSS3: 6.7
nvd
почти 3 года назад

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

msrc
почти 3 года назад

CERT/CC: CVE-2022-34301 Eurosoft Boot Loader Bypass

CVSS3: 6.8
fstec
почти 3 года назад

Уязвимость загрузщика Eurosoft операционных систем Windows, позволяющая нарушителю обойти существующие ограничения безопасности

oracle-oval
около 2 лет назад

ELSA-2023-2487: fwupd security and bug fix update (MODERATE)

EPSS

Процентиль: 17%
0.00053
Низкий

6.7 Medium

CVSS3