PT-2020-12267 · Denx+2 · Das U-Boot+2

Dmitry Janushkevich

+1

·

Published

2020-01-22

·

Updated

2022-11-04

·

CVE-2020-10648

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Das U-Boot versions through 2020.01
Description The issue allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
Recommendations For Das U-Boot versions through 2020.01, consider restricting the ability to provide crafted FIT images to the system as a temporary workaround until a patch is available. As a mitigation measure, ensure that systems are not configured to boot the default configuration unless necessary, and implement additional security controls to prevent unauthorized booting of arbitrary images. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1720
BDU:2025-13598
CVE-2020-10648
OPENSUSE-SU-2020:1869-1
OPENSUSE-SU-2020:1930-1
OPENSUSE-SU-2020_1869-1
OPENSUSE-SU-2020_1930-1
SUSE-SU-2020:3161-1
SUSE-SU-2020:3255-1
SUSE-SU-2020:3256-1
SUSE-SU-2020:3282-1
SUSE-SU-2020:3283-1
SUSE-SU-2020:3474-1
SUSE-SU-2020_3161-1

Affected Products

Alt Linux
Das U-Boot
Suse