V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-10713
AST
High

A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. T…

CVSS
8.2
High
EPSS
0.01
p60
Published
2020-01-01
Updated
2020-01-01
Description

A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Tags · CWE
CWE-120
CWE-787
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-67
CAPEC-92
CAPEC-100
Affected products
FwupdFwupdFwupdFwupdateFwupdateFwupdateFwupdateFwupdateFwupdateGrub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: H
High (H)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.011 · p60
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
fwupdTracked
fwupdTracked
fwupdTracked
fwupdateTracked
fwupdateTracked
fwupdateTracked
fwupdateTracked
fwupdateTracked
fwupdateTracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
Showing first 20 of 97
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities