Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15705

Опубликовано: 29 июл. 2020
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-440
https://bugzilla.redhat.com/show_bug.cgi?id=1860978grub2: Fail kernel validation without shim protocol

EPSS

Процентиль: 5%
0.00024
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
nvd
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 6.4
debian
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without ...

suse-cvrf
почти 5 лет назад

Security update for grub2

EPSS

Процентиль: 5%
0.00024
Низкий

6.4 Medium

CVSS3