PT-2022-4116 · Cryptopro+3 · Cryptopro Secure Disk+3

Jesse Michael

+1

·

Published

2022-08-09

·

Updated

2025-10-15

·

CVE-2022-34301

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CryptoPro Secure Disk versions before 2022-06-01
Description A flaw was found in the bootloaders, allowing an attacker to bypass or tamper with Secure Boot protections. To load and execute arbitrary code in the pre-boot stage, an attacker needs to replace the existing signed bootloader with this one, requiring access to the EFI System Partition for booting using external media. The vulnerability is related to errors in security settings, which can be exploited to bypass existing security restrictions.
Recommendations For versions before 2022-06-01, consider restricting access to the EFI System Partition to minimize the risk of exploitation. As a temporary workaround, avoid using external media for booting until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALSA-2023:2487
BDU:2022-04955
CVE-2022-34301
RHSA-2023:2487
RHSA-2023_2487

Affected Products

Almalinux
Cryptopro Secure Disk
Red Hat
Windows