Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2021-38576

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

  • Published: Jan 3, 2022
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-38576
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: High
  • Score: 7.8
  • AV:N/AC:L/Au:N/C:N/I:N/A:C

No CWE or OWASP classifications available.

Software From Fixed in
tianocore / edk2 202008 202008.x
tianocore / edk2 201905 201905.x
tianocore / edk2 202105 202105.x
tianocore / edk2 202102 202102.x
tianocore / edk2 202011 202011.x
tianocore / edk2 202005 202005.x
tianocore / edk2 202002 202002.x
tianocore / edk2 201911 201911.x
tianocore / edk2 201903 201903.x
tianocore / edk2 201811 201811.x
tianocore / edk2 201808 201808.x
tianocore / edk2 201908 201908.x