Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-38576


A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.


Published

2022-01-03T22:15:09.903

Last Modified

2024-11-21T06:17:33.457

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tianocore edk2 201808 Yes
Application tianocore edk2 201811 Yes
Application tianocore edk2 201903 Yes
Application tianocore edk2 201905 Yes
Application tianocore edk2 201908 Yes
Application tianocore edk2 201911 Yes
Application tianocore edk2 202002 Yes
Application tianocore edk2 202005 Yes
Application tianocore edk2 202008 Yes
Application tianocore edk2 202011 Yes
Application tianocore edk2 202102 Yes
Application tianocore edk2 202105 Yes

References