Show filters
171 Total Results
Displaying 31-40 of 171
Sort by:
Attacker Value
Unknown
CVE-2024-43378
Disclosure Date: August 16, 2024 (last updated August 16, 2024)
calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning to create a setup where the system was booted via legacy BIOS rather than UEFI; some disk partitions are encrypted; but the partitions containing either `/` or `/boot` are unencrypted; have their LUKS disk encryption key file in plain text either in `/crypto_keyfile.bin`, or in a CPIO archive attached to their NixOS initrd. `nixos-install` is not affected, nor are UEFI installations, nor was the default automatic partitioning configuration on legacy BIOS systems. The problem has been fixed in calamares-nixos-extensions 0.3.17, which was included in NixOS. The current installer images for the NixOS 24.05 and unstable (24.11) channels are unaffected. The fix reached 24.05 at 2024-08-13 20:06:59 UTC, and unstable at 2024-08-15 09:00:20 UTC. Installer images downloaded before those times may b…
0
Attacker Value
Unknown
CVE-2024-26022
Disclosure Date: August 14, 2024 (last updated September 07, 2024)
Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-20578
Disclosure Date: August 13, 2024 (last updated October 03, 2024)
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-20518
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
0
Attacker Value
Unknown
CVE-2021-46772
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient input validation in the ABL may allow a privileged
attacker with access to the BIOS menu or UEFI shell to tamper with the
structure headers in SPI ROM causing an out of bounds memory read and write,
potentially resulting in memory corruption or denial of service.
0
Attacker Value
Unknown
CVE-2021-26387
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient access controls in ASP kernel may allow a
privileged attacker with access to AMD signing keys and the BIOS menu or UEFI
shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
0
Attacker Value
Unknown
CVE-2023-28149
Disclosure Date: July 31, 2024 (last updated August 01, 2024)
An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, and 5.6 before 05.60.39 that could allow an attacker to modify UEFI variables.
0
Attacker Value
Unknown
CVE-2023-32466
Disclosure Date: July 24, 2024 (last updated September 12, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
0
Attacker Value
Unknown
CVE-2023-32467
Disclosure Date: July 10, 2024 (last updated September 11, 2024)
Dell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds write vulnerability. A local authenticated malicious user with high privileges could potentially exploit this vulnerability leading to exposure of some UEFI code, leading to arbitrary code execution or escalation of privilege.
0
Attacker Value
Unknown
CVE-2024-0158
Disclosure Date: July 02, 2024 (last updated August 01, 2024)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
0