CVE-2023-4001

CVSS V2 None CVSS V3 None
Description
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
Overview
  • CVE ID
  • CVE-2023-4001
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-01-15T11:10:19.517Z
  • Last Modified Date
  • 2024-05-01T20:20:56.178Z
History
Created Old Value New Value Data Type Notes
2024-06-24 19:15:27 Added to TrackCVE