Verified Boot Bypass in Das U-Boot Open Source Bootloader
CVE-2020-10648

7.8HIGH

Key Information:

Vendor

Denx

Status
Vendor
CVE Published:
19 March 2020

What is CVE-2020-10648?

Das U-Boot, an open-source bootloader, is susceptible to a vulnerability that allows attackers to bypass verified boot restrictions. By exploiting this weakness, an attacker can boot arbitrary images on a system that is configured to utilize the default boot configuration. This poses significant security risks as it can lead to unauthorized access to the system and potential compromise of the underlying hardware and software environment.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.