CVE-2020-15705
MEDIUM severity · CVSS 6.4 · CWE-347
6.4CVSS MEDIUM
Summary
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
Impact & exploitability
Attack vectorLocal
Attack complexityHigh
Privileges requiredHigh
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)2%
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.htmlAdvisory
- http://ubuntu.com/security/notices/USN-4432-1Advisory
- http://www.openwall.com/lists/oss-security/2020/07/29/3Advisory
- http://www.openwall.com/lists/oss-security/2021/03/02/3Advisory
- http://www.openwall.com/lists/oss-security/2021/09/17/2Advisory
- http://www.openwall.com/lists/oss-security/2021/09/17/4Advisory
- http://www.openwall.com/lists/oss-security/2021/09/21/1Advisory