TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-3418

MEDIUM
6.4

Descricao

If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.

Detalhes CVE

Pontuacao CVSS v3.16.4
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosHIGH
Interacao do usuarioNONE
Publicado3/15/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

gnu:grub2

Fraquezas (CWE)

CWE-281

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.