[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-15705Date: (C)2020-07-30   (M)2024-05-03


GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.4CVSS Score : 4.4
Exploit Score: 0.5Exploit Score: 3.4
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: HIGHAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
GLSA-202104-05
USN-4432-1
http://www.openwall.com/lists/oss-security/2020/07/29/3
http://www.openwall.com/lists/oss-security/2021/03/02/3
http://www.openwall.com/lists/oss-security/2021/09/17/2
http://www.openwall.com/lists/oss-security/2021/09/17/4
http://www.openwall.com/lists/oss-security/2021/09/21/1
http://ubuntu.com/security/notices/USN-4432-1
https://access.redhat.com/security/vulnerabilities/grub2bootloader
https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
https://security.netapp.com/advisory/ntap-20200731-0008/
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass
https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
https://www.openwall.com/lists/oss-security/2020/07/29/3
https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
https://www.suse.com/support/kb/doc/?id=000019673
openSUSE-SU-2020:1280
openSUSE-SU-2020:1282

CPE    16
cpe:/o:suse:suse_linux_enterprise_server:15
cpe:/o:suse:suse_linux_enterprise_server:12
cpe:/o:microsoft:windows_10:1809
cpe:/o:microsoft:windows_10:1803
...
CWE    1
CWE-347
OVAL    20
oval:org.secpod.oval:def:89002925
oval:org.secpod.oval:def:89050514
oval:org.secpod.oval:def:89050300
oval:org.secpod.oval:def:89000027
...

© SecPod Technologies