Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-34302

Опубликовано: 11 авг. 2022
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

Отчет

The shim packages distributed with Red Hat Enterprise Linux 7, 8 and 9 is not affected by this issue, however as the 3rd party affected shim is trusted by the UEFI platform an attacker can still use it to subvert secure boot protections in Red Hat Enterprise Linux installed systems. Red Hat is working to provide a DBX update via fwupd package to prevent affected components to be booted successfully.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7fwupdAffected
Red Hat Enterprise Linux 7shimNot affected
Red Hat Enterprise Linux 8fwupdAffected
Red Hat Enterprise Linux 8shimNot affected
Red Hat Enterprise Linux 9shimNot affected
Red Hat Enterprise Linux 9fwupdFixedRHSA-2023:248709.05.2023
Red Hat Enterprise Linux 9fwupdFixedRHSA-2023:248709.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-494
https://bugzilla.redhat.com/show_bug.cgi?id=2120687shim: 3rd party shim allow secure boot bypass

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
почти 3 года назад

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

msrc
почти 3 года назад

CERT/CC: CVE-2022-34302 New Horizon Data Systems Inc Boot Loader Bypass

CVSS3: 6.7
github
почти 3 года назад

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

CVSS3: 6.8
fstec
почти 3 года назад

Уязвимость загрузчика New Horizon Data Systems операционных систем Windows, позволяющая нарушителю обойти существующие ограничения безопасности

oracle-oval
около 2 лет назад

ELSA-2023-2487: fwupd security and bug fix update (MODERATE)

7.5 High

CVSS3