Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-15705
Description:GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
Test IDs: 1.3.6.1.4.1.25623.1.0.853389   1.3.6.1.4.1.25623.1.1.2.2022.1008   1.3.6.1.4.1.25623.1.1.4.2020.2306.1   1.3.6.1.4.1.25623.1.1.2.2022.1028   1.3.6.1.4.1.25623.1.1.4.2020.2307.1   1.3.6.1.4.1.25623.1.0.853391   1.3.6.1.4.1.25623.1.1.4.2020.2308.1   1.3.6.1.4.1.25623.1.1.4.2020.2303.1   1.3.6.1.4.1.25623.1.1.4.2020.14461.1   1.3.6.1.4.1.25623.1.1.4.2020.2304.1   1.3.6.1.4.1.25623.1.1.2.2022.1194   1.3.6.1.4.1.25623.1.1.4.2020.2305.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-15705
https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
https://www.openwall.com/lists/oss-security/2020/07/29/3
Debian Security Information: https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot (Google Search)
https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
https://security.gentoo.org/glsa/202104-05
http://www.openwall.com/lists/oss-security/2020/07/29/3
http://www.openwall.com/lists/oss-security/2021/03/02/3
http://www.openwall.com/lists/oss-security/2021/09/17/2
http://www.openwall.com/lists/oss-security/2021/09/17/4
http://www.openwall.com/lists/oss-security/2021/09/21/1
RedHat Security Advisories: https://access.redhat.com/security/vulnerabilities/grub2bootloader
https://access.redhat.com/security/vulnerabilities/grub2bootloader
SuSE Security Announcement: https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/ (Google Search)
https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
SuSE Security Announcement: https://www.suse.com/support/kb/doc/?id=000019673 (Google Search)
https://www.suse.com/support/kb/doc/?id=000019673
SuSE Security Announcement: openSUSE-SU-2020:1280 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html
SuSE Security Announcement: openSUSE-SU-2020:1282 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html
https://usn.ubuntu.com/4432-1/
http://ubuntu.com/security/notices/USN-4432-1
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass




© 1998-2025 E-Soft Inc. All rights reserved.