A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Sep 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 09 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 30 Aug 2024 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 30 Aug 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-1394 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Mon, 26 Aug 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 26 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised. | |
Title | Insecure Platform Key (PK) used in UEFI system firmware signature | |
References |
|
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2024-08-26T19:15:11.237Z
Updated: 2024-09-09T20:21:06.044Z
Reserved: 2024-08-22T19:50:07.296Z
Link: CVE-2024-8105
Vulnrichment
Updated: 2024-08-30T16:02:49.517Z
NVD
Status : Undergoing Analysis
Published: 2024-08-26T20:15:08.380
Modified: 2024-11-21T09:52:40.667
Link: CVE-2024-8105
Redhat