Vulnerability Name: | CVE-2015-5281 (CCN-108206) | ||||||||||||||||||||||||
Assigned: | 2015-11-17 | ||||||||||||||||||||||||
Published: | 2015-11-17 | ||||||||||||||||||||||||
Updated: | 2016-12-07 | ||||||||||||||||||||||||
Summary: | The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-5281 Source: FEDORA Type: UNKNOWN FEDORA-2015-c3b4fef3af Source: FEDORA Type: UNKNOWN FEDORA-2015-2c155d7632 Source: REDHAT Type: Vendor Advisory RHSA-2015:2401 Source: CCN Type: IBM Security Bulletin T1023376 (PowerKVM) Vulnerabilities in grub2 affect PowerKVM (CVE-2015-5281, CVE-2015-8370) Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html Source: BID Type: UNKNOWN 77983 Source: CCN Type: BID-77983 GNU GRUB2 CVE-2015-5281 Local Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1034198 Source: CCN Type: Red Hat Bugzilla Bug 1264103 (CVE-2015-5281) CVE-2015-5281 grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1264103 Source: XF Type: UNKNOWN grub2-cve20155281-code-exec(108206) Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-5281 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |