CVE-2021-28213Inadequate Encryption Strength in Edk2

Severity
7.5HIGHNVD
EPSS
0.3%
top 49.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 24

Description

Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debiantianocore/edk2< 0~20190606.20d2e5a1-2+3
NVDtianocore/edk2201905
CVEListV5tianocore/edk_iiedk2-stable201905

🔴Vulnerability Details

3
GHSA
GHSA-p38x-2cfm-g52f: Example EDK2 encrypted private key in the IpSecDxe2022-05-24
OSV
CVE-2021-28213: Example EDK2 encrypted private key in the IpSecDxe2021-06-11
CVEList
CVE-2021-28213: Example EDK2 encrypted private key in the IpSecDxe2021-06-11

📋Vendor Advisories

2
Red Hat
edk2: encrypted private key in the IpSecDxe.efi present potential security risks2021-06-11
Debian
CVE-2021-28213: edk2 - Example EDK2 encrypted private key in the IpSecDxe.efi present potential securit...2021
CVE-2021-28213 — Inadequate Encryption Strength in Edk2 | cvebase