CVE-2020-10759
published 2020-09-15CVE-2020-10759: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass…
PriorityP430medium6CVSS 3.1
AVLACLPRHUINSUCHIHAN
EPSS
0.49%
39.4th percentile
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fwupd | < fwupd 1.3.10-1 (bookworm) | fwupd 1.3.10-1 (bookworm) |
| debian | libjcat | < fwupd 1.3.10-1 (bookworm) | fwupd 1.3.10-1 (bookworm) |
| fwupd | fwupd | >= 0 < 1.3.10-1 | 1.3.10-1 |
| fwupd | fwupd | >= 0 < 1.3.10-1 | 1.3.10-1 |
| fwupd | fwupd | >= 0 < 1.3.10-1 | 1.3.10-1 |
| fwupd | fwupd | >= 0 < 1.3.10-1 | 1.3.10-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phhj-vpf5-5666: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware
ghsa_unreviewed·2022-05-24
CVE-2020-10759 [MEDIUM] CWE-347 GHSA-phhj-vpf5-5666: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
OSV
CVE-2020-10759: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware
osv·2020-09-15·CVSS 6.0
CVE-2020-10759 [MEDIUM] CVE-2020-10759: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
Ubuntu
fwupd vulnerability
vendor_ubuntu·2020-06-15
CVE-2020-10759 fwupd vulnerability
Title: fwupd vulnerability
Summary: fwupd could be made to install an unsigned firmware.
Justin Steven discovered that fwupd incorrectly handled certain signature
verification. An attacker could possibly use this issue to install an unsigned
firmware.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
fwupd: Possible bypass in signature verification
vendor_redhat·2020-06-05·CVSS 6.0
CVE-2020-10759 [MEDIUM] CWE-347 fwupd: Possible bypass in signature verification
fwupd: Possible bypass in signature verification
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
A PGP signature bypass flaw was found in fwupd, which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red
Debian
CVE-2020-10759: fwupd - A PGP signature bypass flaw was found in fwupd (all versions), which could lead ...
vendor_debian·2020·CVSS 6.0
CVE-2020-10759 [MEDIUM] CVE-2020-10759: fwupd - A PGP signature bypass flaw was found in fwupd (all versions), which could lead ...
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.
Scope: local
bookworm: resolved (fixed in 1.3.10-1)
bullseye: resolved (fixed in 1.3.10-1)
forky: resolved (fixed in 1.3.10-1)
sid: resolved (fixed in 1.3.10-1)
trixie: resolved (fixed in 1.3.10-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10759 fwupd: Possible bypass in signature verification [fedora-all]
bugzilla·2020-06-05·CVSS 6.0
CVE-2020-10759 [MEDIUM] CVE-2020-10759 fwupd: Possible bypass in signature verification [fedora-all]
CVE-2020-10759 fwupd: Possible bypass in signature verification [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-10759 fwupd: Possible bypass in signature verification
bugzilla·2020-06-05·CVSS 6.0
CVE-2020-10759 [MEDIUM] CVE-2020-10759 fwupd: Possible bypass in signature verification
CVE-2020-10759 fwupd: Possible bypass in signature verification
A PGP signature bypass was found in fwupd, which could lead to possible installation of unsigned firmware.
As per upstream:
* For Red Hat Enterprise Linux 7: LVFS (LVFS (Linux Vendor Firmware Service) is: a secure portal which allows hardware vendors to upload firmware updates. The site is used by all major Linux distributions to provide metadata for clients such as fwupdmgr and GNOME Software.) was never enabled there although the PGP bypass is possible but not implementable.
* For Red Hat Enterprise Linux 8: The LVFS is disabled and never used the Amazon CDN. PGP bypass possible, but not implementable.
More information available at:
https://bugzilla.redhat.com/show_bug.cgi?id=1841462
Discussion:
Acknowledgments:
Name
https://bugzilla.redhat.com/show_bug.cgi?id=1844316https://github.com/justinsteven/advisories/blob/master/2020_fwupd_dangling_s3_bucket_and_CVE-2020-10759_signature_verification_bypass.mdhttps://bugzilla.redhat.com/show_bug.cgi?id=1844316https://github.com/justinsteven/advisories/blob/master/2020_fwupd_dangling_s3_bucket_and_CVE-2020-10759_signature_verification_bypass.md
2020-09-15
Published