« Volver al listado

CVE-2023-49721

Estado: AnalizadaMedia (6.7)—

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-49721",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-49721",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-15T16:55:58.653539Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "vendor": "Canonical Ltd.",
          "product": "LXD",
          "versions": [
            {
              "status": "affected",
              "version": "0"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "lxd"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*"
          ],
          "vendor": "canonical",
          "product": "lxd",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-14T22:15:47.530",
  "references": [
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48733",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2024/02/14/4",
      "tags": [
        "Mailing List"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48733",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.openwall.com/lists/oss-security/2024/02/14/4",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot."
    },
    {
      "lang": "es",
      "value": "Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en LXD. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro."
    }
  ],
  "lastModified": "2026-06-17T06:36:21.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCDFE8E4-47BD-40FE-93BB-FC5106157DDF",
              "versionEndExcluding": "5.21.0",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CE995B2-F287-4E18-B840-6EC5171BBBA5",
              "versionEndIncluding": "2023.11-8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}