Vulnerability Name: | CVE-2021-3418 (CCN-197617) | ||||||||||||
Assigned: | 2021-03-02 | ||||||||||||
Published: | 2021-03-02 | ||||||||||||
Updated: | 2021-03-22 | ||||||||||||
Summary: | If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism. | ||||||||||||
CVSS v3 Severity: | 6.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-281 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-3418 Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1933757 Source: XF Type: UNKNOWN gnugrub-cve20213418-sec-bypass(197617) Source: CCN Type: GRUB GIT Repository GNU GRUB2 Source: CCN Type: oss-sec Mailing List, Tue, 2 Mar 2021 18:13:44 +0000 Multiple GRUB2 vulnerabilities Source: CCN Type: IBM Security Bulletin 6475265 (QRadar SIEM) GRUB2 as used by IBM QRadar SIEM is vulnerable to arbitrary code execution | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |