Description
EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."
Published: 2026-08-27
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

EAZ EazyFix 12.9 has a missing cryptographic step that allows a security feature bypass related to disabling secure boot. This flaw enables an attacker to circumvent controls intended to protect the secure boot configuration, potentially allowing unauthorized changes to system settings or elevated privileges. The weakness is classified as CWE-325, indicating improper handling of authentication or cryptographic checks.

Affected Systems

The affected system is EazyFix 12.9 produced by eazsolution. No additional versions or products were listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.0 indicates a medium severity impact. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is not explicitly defined in the description, so it is inferred that at least local or privileged access is required to exploit the missing cryptographic step that controls secure boot disabling.

Generated by OpenCVE AI on August 28, 2026 at 05:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade EazyFix to a version that incorporates the missing cryptographic step fix.
  • If an update is not available, disable the secure boot disable feature or enforce a strict secure boot policy.
  • Implement monitoring or logging for any changes to secure boot settings so that unauthorized alterations are detected promptly.

Generated by OpenCVE AI on August 28, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable."
Weaknesses CWE-325
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T16:55:27.336Z

Reserved: 2026-02-01T04:15:28.819Z

Link: CVE-2026-25250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:18.243

Modified: 2026-08-27T20:17:18.243

Link: CVE-2026-25250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:00:14Z

Weaknesses
  • CWE-325

    Missing Cryptographic Step