Количество 2
Количество 2
CVE-2025-4275
A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot.
GHSA-v9r5-7mg9-fwrr
Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-4275 A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-v9r5-7mg9-fwrr Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу