Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38798

Опубликовано: 09 дек. 2025
Источник: redhat
CVSS3: 5.2
EPSS Низкий

Описание

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

A flaw was found in EDK2. This vulnerability allows information disclosure or escalation of privilege via local access to the BIOS (Basic Input/Output System).

Отчет

This vulnerability is rated Moderate for Red Hat as it requires local access to the system. The flaw in EDK2, a BIOS component, could lead to information disclosure or escalation of privilege by an attacker with local access. This primarily affects the underlying hardware firmware.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10edk2Fix deferred
Red Hat Enterprise Linux 8edk2Fix deferred
Red Hat Enterprise Linux 9edk2Fix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2420643EDK2: EDK2: Information Disclosure and Privilege Escalation via Local BIOS Access

EPSS

Процентиль: 3%
0.00126
Низкий

5.2 Medium

CVSS3

Связанные уязвимости

ubuntu
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

nvd
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

debian
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause \u20 ...

github
8 месяцев назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.

CVSS3: 7
fstec
8 месяцев назад

Уязвимость среды с открытым исходным кодом для разработки UEFI EDK2, связанная с раскрытием информации, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 3%
0.00126
Низкий

5.2 Medium

CVSS3