Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-8105

Опубликовано: 26 авг. 2024
Источник: nvd
CVSS3: 6.4
EPSS Низкий

Описание

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

EPSS

Процентиль: 19%
0.00274
Низкий

6.4 Medium

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 8.2
redhat
около 2 лет назад

A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in possession of the corresponding PK private key can sign arbitrary UEFI executables or firmware components, causing them to be trusted by affected systems and potentially bypassing UEFI Secure Boot trust validation.

CVSS3: 6.4
github
около 2 лет назад

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

CVSS3: 8.2
fstec
около 2 лет назад

Уязвимость микропрограммного обеспечения UEFI (BIOS), связанная с возможностью использования жёстко закодированных ключей платформы, позволяющая нарушителю выполнить произвольный код до загрузки операционной системы

EPSS

Процентиль: 19%
0.00274
Низкий

6.4 Medium

CVSS3

Дефекты