Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3r2-464w-g5x4

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

EPSS

Процентиль: 13%
0.00042
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.4
nvd
почти 8 лет назад

Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with physical access to the system could boot unsigned code.

EPSS

Процентиль: 13%
0.00042
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-287