PT-2025-49977 · Edk2+1 · Edk2+1

Published

2024-01-01

·

Updated

2025-12-12

·

CVE-2024-38798

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions EDK2 (affected versions not specified)
Description EDK2 contains a flaw in BIOS that could allow an attacker with local access to expose sensitive information. Successful exploitation may lead to information disclosure or privilege escalation, impacting confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05137
CVE-2024-38798
GHSA-Q2C6-37H5-7CWF

Affected Products

Debian
Edk2