CVE-2023-49721
published 2024-02-14CVE-2023-49721: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
PriorityP432medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.24%
14.7th percentile
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | lxd | >= 5.0.0 < 5.21.0 | 5.21.0 |
| canonical_ltd | lxd | — | — |
| debian | incus | — | — |
| debian | lxd | — | — |
| tianocore | edk2 | <= 2023.11-8 | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_debian6.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4639-7gfm-29p2: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD
ghsa_unreviewed·2024-02-15
CVE-2023-49721 [MEDIUM] CWE-276 GHSA-4639-7gfm-29p2: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Debian
CVE-2023-49721: incus - An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This al...
vendor_debian·2023·CVSS 6.7
CVE-2023-49721 [MEDIUM] CVE-2023-49721: incus - An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This al...
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139https://nvd.nist.gov/vuln/detail/CVE-2023-48733https://www.openwall.com/lists/oss-security/2024/02/14/4https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139https://nvd.nist.gov/vuln/detail/CVE-2023-48733https://www.openwall.com/lists/oss-security/2024/02/14/4
2024-02-14
Published