7.8

CVE-2021-38576

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Data is provided by the National Vulnerability Database (NVD)
TianocoreEdk2 Version201808
TianocoreEdk2 Version201811
TianocoreEdk2 Version201903
TianocoreEdk2 Version201905
TianocoreEdk2 Version201908
TianocoreEdk2 Version201911
TianocoreEdk2 Version202002
TianocoreEdk2 Version202005
TianocoreEdk2 Version202008
TianocoreEdk2 Version202011
TianocoreEdk2 Version202102
TianocoreEdk2 Version202105
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.398
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C