Описание
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
A flaw was found in EDK2. This vulnerability allows information disclosure or escalation of privilege via local access to the BIOS (Basic Input/Output System).
Отчет
This vulnerability is rated Moderate for Red Hat as it requires local access to the system. The flaw in EDK2, a BIOS component, could lead to information disclosure or escalation of privilege by an attacker with local access. This primarily affects the underlying hardware firmware.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | edk2 | Fix deferred | ||
| Red Hat Enterprise Linux 8 | edk2 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | edk2 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.2 Medium
CVSS3
Связанные уязвимости
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
EDK2 contains a vulnerability in BIOS where an attacker may cause \u20 ...
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
Уязвимость среды с открытым исходным кодом для разработки UEFI EDK2, связанная с раскрытием информации, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации
EPSS
5.2 Medium
CVSS3