CVE-2022-3675
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any security fixes that have recently been applied to the machine. A password is still required to modify kernel command-line arguments and to access the GRUB command line.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-306
Referencias
- https://docs.fedoraproject.org/en-US/fedora-coreos/grub-password/
- https://github.com/coreos/fedora-coreos-tracker/issues/1333
- https://lists.fedoraproject.org/archives/list/coreos-status@lists.fedoraproject.org/thread/NHUCNH5Y4UH5DPUCXISYXXVA563TLFEJ/
- https://docs.fedoraproject.org/en-US/fedora-coreos/grub-password/
- https://github.com/coreos/fedora-coreos-tracker/issues/1333
- https://lists.fedoraproject.org/archives/list/coreos-status@lists.fedoraproject.org/thread/NHUCNH5Y4UH5DPUCXISYXXVA563TLFEJ/
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-3675",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-3675",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-02T18:53:02.484531Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 2.6,
"attackVector": "PHYSICAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 0.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "patrick@puiterwijk.org",
"affectedData": [
{
"vendor": "Fedora Project",
"product": "CoreOS",
"versions": [
{
"status": "affected",
"version": "testing 36.20220906.2.0 and later",
"lessThan": "testing 36.20221030.2.0 ",
"versionType": "fix"
},
{
"status": "affected",
"version": "next 36.20220906.1.0 and later",
"lessThan": "next 37.20221031.1.0",
"versionType": "fix"
},
{
"status": "affected",
"version": "stable 36.20220820.3.0 and later",
"lessThan": "stable 36.20221014.3.0",
"versionType": "fix"
}
],
"packageName": "coreos-assembler",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2022-11-03T18:15:14.627",
"references": [
{
"url": "https://docs.fedoraproject.org/en-US/fedora-coreos/grub-password/",
"tags": [
"Vendor Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://github.com/coreos/fedora-coreos-tracker/issues/1333",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/coreos-status@lists.fedoraproject.org/thread/NHUCNH5Y4UH5DPUCXISYXXVA563TLFEJ/",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "patrick@puiterwijk.org"
},
{
"url": "https://docs.fedoraproject.org/en-US/fedora-coreos/grub-password/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/coreos/fedora-coreos-tracker/issues/1333",
"tags": [
"Issue Tracking",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/coreos-status@lists.fedoraproject.org/thread/NHUCNH5Y4UH5DPUCXISYXXVA563TLFEJ/",
"tags": [
"Mailing List",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "patrick@puiterwijk.org",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Fedora CoreOS supports setting a GRUB bootloader password\nusing a Butane config. When this feature is enabled, GRUB requires a password to access the\nGRUB command-line, modify kernel command-line arguments, or boot\nnon-default OSTree deployments. Recent Fedora CoreOS releases have a\nmisconfiguration which allows booting non-default OSTree deployments\nwithout entering a password. This allows someone with access to the\nGRUB menu to boot into an older version of Fedora CoreOS, reverting\nany security fixes that have recently been applied to the machine. A\npassword is still required to modify kernel command-line arguments and\nto access the GRUB command line.\n\n\n\n"
},
{
"lang": "es",
"value": "Fedora CoreOS admite la configuración de una contraseña del cargador de arranque GRUB usando una configuración de Butane. Cuando esta característica está habilitada, GRUB requiere una contraseña para acceder a la línea de comandos de GRUB, modificar los argumentos de la línea de comandos del kernel o iniciar implementaciones de OSTree no predeterminadas. Las versiones recientes de Fedora CoreOS tienen una configuración incorrecta que permite iniciar implementaciones OSTree no predeterminadas sin ingresar una contraseña. Esto permite que alguien con acceso al menú de GRUB inicie una versión anterior de Fedora CoreOS, revirtiendo cualquier corrección de seguridad que se haya aplicado recientemente a la máquina. Aún se requiere una contraseña para modificar los argumentos de la línea de comandos del kernel y acceder a la línea de comandos de GRUB."
}
],
"lastModified": "2026-06-17T04:59:59.683",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:fedora_coreos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E39CD0D4-960C-48F7-BD25-1362B062C27B",
"versionEndExcluding": "37.20221031.1.0",
"versionStartIncluding": "36.20220820.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "patrick@puiterwijk.org"
}