Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18070 | A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot. |
Solution
kernel 5.2, Version 05.2A.16 kernel 5.3, Version 05.39.16 kernel 5.4, Version 05.47.16 kernel 5.5, Version 05.55.16 kernel 5.6, Version 05.62.16 kernel 5.7, Version 05.71.16
Workaround
No workaround given by the vendor.
Wed, 30 Jul 2025 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. | A vulnerability in the digital signature verification process does not properly validate variable attributes which allows an attacker to bypass signature verification by creating a non-authenticated NVRAM variable. An attacker may to execute arbitrary signed UEFI code and bypass Secure Boot. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Running the provided utility changes the certificate on any Insyde BIOS and then the attached .efi file can be launched. | |
| Title | SecureFlashDxe: Incorrect UEFI variable attributes check allows usage of invalid certificate | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Insyde
Published:
Updated: 2025-08-14T05:58:07.245Z
Reserved: 2025-05-05T01:59:27.834Z
Link: CVE-2025-4275
Updated: 2025-06-11T01:32:11.159Z
Status : Awaiting Analysis
Published: 2025-06-11T01:15:20.750
Modified: 2025-07-30T08:15:34.240
Link: CVE-2025-4275
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD