Логотип exploitDog
bind:"GHSA-j6wm-c7q8-jcx7" OR bind:"CVE-2021-3418"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-j6wm-c7q8-jcx7" OR bind:"CVE-2021-3418"

Количество 9

Количество 9

github логотип

GHSA-j6wm-c7q8-jcx7

около 3 лет назад

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grbu2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

EPSS: Низкий
ubuntu логотип

CVE-2021-3418

больше 4 лет назад

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2021-3418

больше 4 лет назад

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2021-3418

больше 4 лет назад

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-3418

около 4 лет назад

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2021-3418

больше 4 лет назад

If certificates that signed grub are installed into db, grub can be bo ...

CVSS3: 6.4
EPSS: Низкий
fstec логотип

BDU:2022-05896

больше 4 лет назад

Уязвимость реализации механизма верификации shim_lock загрузчика операционных систем Grub2, позволяющая нарушителю выполнить произвольный код и получить полный контроль над устройством

CVSS3: 6.4
EPSS: Низкий
msrc логотип

ADV200011

почти 4 года назад

Microsoft Guidance for Addressing Security Feature Bypass in GRUB

EPSS: Низкий
redos логотип

ROS-20220920-01

почти 3 года назад

Множественные уязвимости GRUB

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j6wm-c7q8-jcx7

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grbu2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-3418

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-3418

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-3418

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-3418

If certificates that signed grub are installed into db, grub can be bo ...

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2022-05896

Уязвимость реализации механизма верификации shim_lock загрузчика операционных систем Grub2, позволяющая нарушителю выполнить произвольный код и получить полный контроль над устройством

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
msrc логотип
ADV200011

Microsoft Guidance for Addressing Security Feature Bypass in GRUB

почти 4 года назад
redos логотип
ROS-20220920-01

Множественные уязвимости GRUB

почти 3 года назад

Уязвимостей на страницу