7.8
CVSSv2

CVE-2021-38576

Published: 03/01/2022 Updated: 13/01/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tianocore edk2 201808

tianocore edk2 201811

tianocore edk2 201903

tianocore edk2 201905

tianocore edk2 201908

tianocore edk2 201911

tianocore edk2 202002

tianocore edk2 202005

tianocore edk2 202008

tianocore edk2 202011

tianocore edk2 202102

tianocore edk2 202105

Vendor Advisories

Debian Bug report logs - #1014468 edk2: CVE-2021-38576 CVE-2021-38577 CVE-2021-38578 Package: src:edk2; Maintainer for src:edk2 is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 6 Jul 2022 15:21:02 UTC Severity: normal Tags: security, upstream ...