« Volver al listado

CVE-2023-48733

Estado: AnalizadaMedia (6.7)—

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-48733",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-48733",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-15T16:17:59.516818Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "vendor": "Canonical Ltd.",
          "product": "Ubuntu EDK II",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2023.05-2ubuntu0.1",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "edk2"
        }
      ]
    }
  ],
  "published": "2024-02-14T22:15:47.320",
  "references": [
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html",
      "tags": [
        "Mailing List"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48733",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2024/02/14/4",
      "tags": [
        "Mailing List"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48733",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2024/02/14/4",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1188"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot."
    },
    {
      "lang": "es",
      "value": "Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en EDK2 de Ubuntu. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro."
    }
  ],
  "lastModified": "2026-06-17T06:34:51.493",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B09DDCF-2D2C-4670-BEDF-5C3574AE0595"
            },
            {
              "criteria": "cpe:2.3:a:canonical:lxd:5.21:candidate:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0707C567-7592-4564-86C3-427B4883E491"
            },
            {
              "criteria": "cpe:2.3:a:canonical:lxd:5.21:edge:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E7C13D8-BD34-44CA-B66A-328FD0A99919"
            },
            {
              "criteria": "cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CE995B2-F287-4E18-B840-6EC5171BBBA5",
              "versionEndIncluding": "2023.11-8"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}