No analysis available yet.
Vendor Solution
kernel 5.2, Version 05.2A.16 kernel 5.3, Version 05.39.16 kernel 5.4, Version 05.47.16 kernel 5.5, Version 05.55.16 kernel 5.6, Version 05.62.16 kernel 5.7, Version 05.71.16
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18070 | A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot. |
Wed, 30 Jul 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. | A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. | |
| Title | SecureFlashDxe: Incorrect UEFI variable attributes check allows usage of invalid certificate | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Insyde
Published:
Updated: 2025-08-14T05:58:07.245Z
Reserved: 2025-05-05T01:59:27.834Z
Link: CVE-2025-4275
Updated: 2025-06-11T01:32:11.159Z
Status : Deferred
Published: 2025-06-11T01:15:20.750
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4275
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD