Vulnerability Database

290,301

Total vulnerabilities in the database

CVE-2018-3968

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

  • Published: Mar 21, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2018-3968
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7
  • AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Low
  • Score: 4.4
  • AV:L/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
denx / u-boot 2013.07-rc1 2013.07-rc1.x
denx / u-boot 2013.07-rc2 2013.07-rc2.x
denx / u-boot 2013.07-rc3 2013.07-rc3.x
denx / u-boot 2013.07 2014.07.x
denx / u-boot 2014.07-rc1 2014.07-rc1.x
denx / u-boot 2014.07-rc2 2014.07-rc2.x