cbcvebase.

Tianocore Edk2 vulnerabilities

52 known vulnerabilities affecting tianocore/edk2.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH27MEDIUM21LOW1

Vulnerabilities

Page 2 of 3
CVE-2018-12179P3HIGHCVSS 7.8≥ 0, < 0~20190606.20d2e5a1-22019-03-27
CVE-2018-12179 [HIGH] CVE-2018-12179: Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclos Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
osv
CVE-2021-28213P3HIGHCVSS 7.5v2019052021-06-11
CVE-2021-28213 [HIGH] CVE-2021-28213: Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks. Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
nvdosv
CVE-2019-14563P3HIGHCVSS 7.8≥ 0, < 0~20200229.4c0f6e34-12020-11-23
CVE-2019-14563 [HIGH] CVE-2019-14563: Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
osv
CVE-2019-14575P3HIGHCVSS 7.8≥ 0, < 0~20200229.4c0f6e34-12020-11-23
CVE-2019-14575 [HIGH] CVE-2019-14575: Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
osv
CVE-2021-28216P4HIGHCVSS 7.8≥ 0, < 2020.11-2+deb11u3≥ 0, < 2021.11~rc1-12021-08-05
CVE-2021-28216 [HIGH] CVE-2021-28216: BootPerformanceTable pointer is read from an NVRAM variable in PEI BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
osv
CVE-2017-5731P4HIGHCVSS 7.8fixed in 2017-11-072019-10-28
CVE-2017-5731 [HIGH] CWE-119 CVE-2017-5731: Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentia Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.
nvdosv
CVE-2019-14584P4HIGHCVSS 7.8fixed in 2020-10-212021-06-03
CVE-2019-14584 [HIGH] CWE-476 CVE-2019-14584: Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable esc Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvdosv
CVE-2025-3770P3HIGHCVSS 7.0≤ edk2-stable2025052025-08-07
CVE-2025-3770 [HIGH] CWE-693 CVE-2025-3770: EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availability.
nvdosv
CVE-2018-3613P4HIGHCVSS 7.8≥ 0, < 0~20160408.ffea0a2c-2ubuntu0.2+esm1≥ 0, < 0~20180205.c0d9813c-2ubuntu0.3+esm12019-03-27
CVE-2018-3613 [HIGH] CVE-2018-3613: Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privileg Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
osv
CVE-2023-48733P4MEDIUMCVSS 6.7≤ 2023.11-82024-02-14
CVE-2023-48733 [MEDIUM] CWE-1188 CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
nvdosv
CVE-2023-49721P4MEDIUMCVSS 6.7≤ 2023.11-82024-02-14
CVE-2023-49721 [MEDIUM] CWE-276 CVE-2023-49721: An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
nvd
CVE-2023-45229P4MEDIUMCVSS 6.5≤ 202311vedk2-stable2023082024-01-16
CVE-2023-45229 [MEDIUM] CWE-125 CVE-2023-45229: EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
nvdosv
CVE-2023-45231P4MEDIUMCVSS 6.5≤ 202311vedk2-stable2023082024-01-16
CVE-2023-45231 [MEDIUM] CWE-125 CVE-2023-45231: EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neigh EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing Neighbor Discovery Redirect message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.
nvdosv
CVE-2024-38796P4MEDIUMCVSS 5.9≤ edk2-stable2024052024-09-27
CVE-2024-38796 [MEDIUM] CWE-122 CVE-2024-38796: EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corru EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability.
nvdosv
CVE-2014-8271P4MEDIUMCVSS 6.8fixed in svn_16280vbefore SVN 162802020-02-06
CVE-2014-8271 [MEDIUM] CWE-120 CVE-2014-8271: Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proxima Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
nvd
CVE-2021-28211P4MEDIUMCVSS 6.7v2020082021-06-11
CVE-2021-28211 [MEDIUM] CWE-122 CVE-2021-28211: A heap overflow in LzmaUefiDecompressGetInfo function in EDK II. A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
nvdosv
CVE-2024-38805P4MEDIUMCVSS 6.3≤ edk2-stable2025022025-08-12
CVE-2024-38805 [MEDIUM] CWE-190 CVE-2024-38805: EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by ne EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
nvdosv
CVE-2018-12183P4MEDIUMCVSS 6.8≥ 0, < 0~20181115.85588389-12019-03-27
CVE-2018-12183 [MEDIUM] CVE-2018-12183: Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or de Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
osv
CVE-2019-11098P4MEDIUMCVSS 6.8≥ 0, < 0~20191122.bd85bf54-2ubuntu3.32021-09-23
CVE-2019-11098 [MEDIUM] edk2 vulnerabilities edk2 vulnerabilities It was discovered that EDK II incorrectly handled input validation in MdeModulePkg. A local user could possibly use this issue to cause EDK II to crash, resulting in a denial of service, obtain sensitive information or execute arbitrary code. (CVE-2019-11098) Paul Kehrer discovered that OpenSSL used in EDK II incorrectly handled certain input lengths in EVP functions. An attacker could possibly use this issue to cause EDK II to
osv
CVE-2018-12182P4MEDIUMCVSS 6.7≥ 0, < 0~20160408.ffea0a2c-2ubuntu0.2+esm1≥ 0, < 0~20180205.c0d9813c-2ubuntu0.3+esm12019-03-27
CVE-2018-12182 [MEDIUM] CVE-2018-12182: Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information d Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
osv
Tianocore Edk2 vulnerabilities | cvebase