grub2
cpe:2.3:a:gnu:grub:*:*:*:*:*:*:*, +1 more
A vulnerability exists in Grub2 where the 'dump' command is not restricted during lockdown mode. This oversight enables users to access memory information, potentially allowing attackers to extract sensitive data such as signatures and salts from memory. This issue has been identified in multiple Red Hat Enterprise Linux versions and Red Hat OpenShift Container Platform 4.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information stored in memory, including cryptographic signatures and salts.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.