7.8

CVE-2021-38576

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TianocoreEdk2 Version201808
TianocoreEdk2 Version201811
TianocoreEdk2 Version201903
TianocoreEdk2 Version201905
TianocoreEdk2 Version201908
TianocoreEdk2 Version201911
TianocoreEdk2 Version202002
TianocoreEdk2 Version202005
TianocoreEdk2 Version202008
TianocoreEdk2 Version202011
TianocoreEdk2 Version202102
TianocoreEdk2 Version202105
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.398
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C