IM
IronMonkey Threat Research

CVE-2020-27779 HIGH

Published: 2021-03-03 | Last Modified: 2024-11-21 | Status: Modified

Description

A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Additional Descriptions (1)

Se encontró un fallo en grub2 en versiones anteriores a 2.06. El comando cutmem no respeta el bloqueo de secure boot, permitiendo a un atacante privilegiado eliminar rangos de direcciones de la memoria, creando una oportunidad para omitir unas protecciones de SecureBoot después de una clasificación apropiada sobre el diseño de la memoria de grub. La mayor amenaza de esta vulnerabilidad es la confidencialidad e integridad de los datos, así como la disponibilidad del sistema

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityHIGH
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 0.8

Impact Score: 6.0

Base Score: 6.9 (MEDIUM)

AV:L/AC:M/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.4

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-285
[email protected] Primary
en NVD-CWE-Other

Affected Products

Vendor Product Version Update Type
gnu grub2 * <built-in method update of dict object at 0x72a963c6b240> Application
redhat enterprise_linux 7.0 <built-in method update of dict object at 0x72a961ec9b40> Operating System
redhat enterprise_linux 8.0 <built-in method update of dict object at 0x72a961ec98c0> Operating System
redhat enterprise_linux_server_aus 7.2 <built-in method update of dict object at 0x72a961eca640> Operating System
redhat enterprise_linux_server_aus 7.3 <built-in method update of dict object at 0x72a963c6a400> Operating System
redhat enterprise_linux_server_aus 7.4 <built-in method update of dict object at 0x72a963c68980> Operating System
redhat enterprise_linux_server_aus 7.6 <built-in method update of dict object at 0x72a961ec9680> Operating System
redhat enterprise_linux_server_aus 7.7 <built-in method update of dict object at 0x72a961ec8100> Operating System
redhat enterprise_linux_server_aus 8.2 <built-in method update of dict object at 0x72a963c6bcc0> Operating System
redhat enterprise_linux_server_eus 7.6 <built-in method update of dict object at 0x72a963c69dc0> Operating System
redhat enterprise_linux_server_eus 7.7 <built-in method update of dict object at 0x72a9b0cfab40> Operating System
redhat enterprise_linux_server_eus 8.1 <built-in method update of dict object at 0x72a961ec9640> Operating System
redhat enterprise_linux_server_tus 7.4 <built-in method update of dict object at 0x72a963c680c0> Operating System
redhat enterprise_linux_server_tus 7.6 <built-in method update of dict object at 0x72a999778c40> Operating System
redhat enterprise_linux_server_tus 7.7 <built-in method update of dict object at 0x72a999779740> Operating System
redhat enterprise_linux_server_tus 8.2 <built-in method update of dict object at 0x72a99977a580> Operating System
redhat enterprise_linux_workstation 7.0 <built-in method update of dict object at 0x72a999779b80> Operating System
fedoraproject fedora 33 <built-in method update of dict object at 0x72a963c69680> Operating System
fedoraproject fedora 34 <built-in method update of dict object at 0x72a963c68f80> Operating System
netapp ontap_select_deploy_administration_utility - <built-in method update of dict object at 0x72a961ec9880> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_eus:7.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_eus:8.1:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
Yes cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
Yes cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
Notification
Message here