cbcvebase.
CVE-2020-10713
published 2020-07-30

CVE-2020-10713: A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows…

PriorityP182high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.07%
60.9th percentile
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as gaining physical access, obtain the ability to alter a pxe-boot network, or have remote access to a networked system with root access. With this access, an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiangrub2< grub2 2.04-9 (bookworm)grub2 2.04-9 (bookworm)
gnugrub2< 2.062.06
gnugrub2>= 0 < 2.04-92.04-9
gnugrub2>= 0 < 2.04-92.04-9
gnugrub2>= 0 < 2.04-92.04-9
gnugrub2>= 0 < 2.04-92.04-9
gnugrub2>= 0 < 2.02~beta2-36ubuntu3.262.02~beta2-36ubuntu3.26
gnugrub2>= 0 < 2.02~beta2-36ubuntu3.272.02~beta2-36ubuntu3.27
gnugrub2>= 0 < 2.02-2ubuntu8.162.02-2ubuntu8.16
gnugrub2>= 0 < 2.02-2ubuntu8.172.02-2ubuntu8.17
gnugrub2>= 0 < 2.04-1ubuntu26.12.04-1ubuntu26.1
gnugrub2>= 0 < 2.04-1ubuntu26.22.04-1ubuntu26.2
gnugrub2>= 0 < 2.02~beta2-9ubuntu1.202.02~beta2-9ubuntu1.20
gnugrub2>= 0 < 2.02~beta2-9ubuntu1.212.02~beta2-9ubuntu1.21
msrccbl2_grub2_2.06rc1-7_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_grub2_2.06rc1-4_on_cbl_mariner_1.0
opensuseleap
opensuseleap
paloaltopan-os
paloaltoprisma_access

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by a crafted GRUB2 configuration file (grub.cfg) that causes a buffer overflow via incorrect bounds checking of parsed values; monitor for unexpected modifications to grub.cfg on managed systems.
  • Exploitation requires prior access via physical access, PXE-boot network manipulation, or remote root access; alert on unauthorized PXE boot configuration changes or unexpected remote root logins preceding boot-time anomalies.
  • Successful exploitation allows arbitrary code execution before the OS loads and can bypass UEFI Secure Boot; monitor for Secure Boot policy violations or unexpected pre-OS execution events in firmware/UEFI logs.
  • ·No mitigation exists for this flaw according to Red Hat; patching is the only remediation path.
  • ·Cisco products are affected; track Cisco Bug IDs CSCvv04959, CSCvv04957, and CSCvv05161 for vendor-specific patch availability.
  • ·Debian resolves the issue in grub2 version 2.04-9 across bookworm, bullseye, forky, sid, and trixie; ensure patched version is deployed.
  • ·Red Hat Enterprise Linux kernel and kernel-rt packages are being updated to contain a new Red Hat certificate for Secure Boot as part of the remediation chain.

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.2HIGH
vulncheck8.2HIGH
vendor_debian8.2HIGH
vendor_msrc8.2HIGH
vendor_redhat8.2HIGH
vendor_ubuntu8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.