CVE-2020-10759 — Improper Verification of Cryptographic Signature in Fwupd
Severity
6.0MEDIUMNVD
EPSS
0.0%
top 99.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 15
Latest updateMay 24
Description
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NExploitability: 0.8 | Impact: 5.2
Affected Packages3 packages
Also affects: Enterprise Linux 7.0, 8.0
🔴Vulnerability Details
2GHSA▶
GHSA-phhj-vpf5-5666: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware↗2022-05-24
OSV▶
CVE-2020-10759: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware↗2020-09-15