CVE-2018-1000205
5.5
MEDIUM
CVSS 3.1
EPSS 0.18%
Description
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special device memory functionality.
How to fix CVE-2018-1000205
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/u-boot—no fix listed
Is CVE-2018-1000205 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |