7.8

CVE-2021-38576

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tianocore ≫ Edk2 Version 201808
Tianocore ≫ Edk2 Version 201811
Tianocore ≫ Edk2 Version 201903
Tianocore ≫ Edk2 Version 201905
Tianocore ≫ Edk2 Version 201908
Tianocore ≫ Edk2 Version 201911
Tianocore ≫ Edk2 Version 202002
Tianocore ≫ Edk2 Version 202005
Tianocore ≫ Edk2 Version 202008
Tianocore ≫ Edk2 Version 202011
Tianocore ≫ Edk2 Version 202102
Tianocore ≫ Edk2 Version 202105
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.17% 0.634
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bugzilla.tianocore.org/show_bug.cgi?id=3499
Third Party Advisory
Issue Tracking
Permissions Required
https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html