A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
References
Link | Resource |
---|---|
https://bugzilla.tianocore.org/show_bug.cgi?id=3499 | Issue Tracking Permissions Required Third Party Advisory |
https://bugzilla.tianocore.org/show_bug.cgi?id=3499 | Issue Tracking Permissions Required Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.tianocore.org/show_bug.cgi?id=3499 - Issue Tracking, Permissions Required, Third Party Advisory |
13 Jan 2022, 16:21
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://bugzilla.tianocore.org/show_bug.cgi?id=3499 - Issue Tracking, Permissions Required, Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:tianocore:edk2:202005:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201808:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201908:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201905:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:202011:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201903:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:202002:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201911:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:202102:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:201811:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:202105:*:*:*:*:*:*:* cpe:2.3:a:tianocore:edk2:202008:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 7.8
v3 : 7.5 |
03 Jan 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-01-03 22:15
Updated : 2024-11-21 06:17
NVD link : CVE-2021-38576
Mitre link : CVE-2021-38576
CVE.ORG link : CVE-2021-38576
JSON object : View
Products Affected
tianocore
- edk2
CWE