6.8
CVSSv2

CVE-2020-10648

Published: 19/03/2020 Updated: 26/03/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Das U-Boot up to and including 2020.01 allows malicious users to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

denx u-boot

denx u-boot 2020.01

opensuse leap 15.2

Vendor Advisories

An insufficient validation issue has been found in U-Boot versions 201803 and 20200 Versions prior to 201803 may be affected as well An attacker having a properly signed FIT image is able to craft arbitrary FIT images that would pass signature validation, resulting in booting and execution of untrusted code The exploitation relies on the fact ...