Логотип exploitDog
bind: "CVE-2023-4001"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-4001"

Количество 9

Количество 9

ubuntu логотип

CVE-2023-4001

больше 1 года назад

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2023-4001

больше 1 года назад

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2023-4001

больше 1 года назад

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2023-4001

12 месяцев назад

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2023-4001

больше 1 года назад

An authentication bypass flaw was found in GRUB due to the way that GR ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-rr4v-xrwq-7rhx

больше 1 года назад

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 5.6
EPSS: Низкий
oracle-oval логотип

ELSA-2024-0468

больше 1 года назад

ELSA-2024-0468: grub2 security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-00324

больше 1 года назад

Уязвимость механизма защиты паролем загрузчика операционных систем Grub2, позволяющая нарушителю обойти установленный контроль доступа

CVSS3: 5.6
EPSS: Низкий
redos логотип

ROS-20240402-06

около 1 года назад

Уязвимость grub2

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 6.8
0%
Низкий
12 месяцев назад
debian логотип
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GR ...

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-rr4v-xrwq-7rhx

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.

CVSS3: 5.6
0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-0468

ELSA-2024-0468: grub2 security update (MODERATE)

больше 1 года назад
fstec логотип
BDU:2024-00324

Уязвимость механизма защиты паролем загрузчика операционных систем Grub2, позволяющая нарушителю обойти установленный контроль доступа

CVSS3: 5.6
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240402-06

Уязвимость grub2

CVSS3: 5.6
0%
Низкий
около 1 года назад

Уязвимостей на страницу