CVE-2023-48733

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/02/2024
Last modified:
26/08/2025

Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:candidate:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:edge:*:*:*:*:*:*
cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:* 2023.11-8 (including)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*