CVE-2023-48733

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:candidate:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:edge:*:*:*:*:*:*
cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

26 Aug 2025, 17:19

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - Issue Tracking
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - Issue Tracking
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html - Mailing List
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - Third Party Advisory
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 - Mailing List
CPE cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:edge:*:*:*:*:*:*
cpe:2.3:a:canonical:lxd:5.21:candidate:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
First Time Canonical lxd
Tianocore
Debian debian Linux
Canonical
Tianocore edk2
Debian

08 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-1188

21 Nov 2024, 08:32

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 - () https://bugs.launchpad.net/ubuntu/+source/edk2/+bug/2040137 -
References () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 - () https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139 -
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html -
References () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 - () https://nvd.nist.gov/vuln/detail/CVE-2023-48733 -
References () https://www.openwall.com/lists/oss-security/2024/02/14/4 - () https://www.openwall.com/lists/oss-security/2024/02/14/4 -

30 Jun 2024, 23:15

Type Values Removed Values Added
Summary
  • (es) Un valor predeterminado inseguro para permitir UEFI Shell en EDK2 se dejó habilitado en EDK2 de Ubuntu. Esto permite que un atacante residente en el sistema operativo omita el arranque seguro.
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00028.html -

14 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-14 22:15

Updated : 2025-08-26 17:19


NVD link : CVE-2023-48733

Mitre link : CVE-2023-48733

CVE.ORG link : CVE-2023-48733


JSON object : View

Products Affected

canonical

  • lxd

debian

  • debian_linux

tianocore

  • edk2
CWE
CWE-1188

Insecure Default Initialization of Resource