CVE Vulnerabilities

CVE-2023-20518

Incomplete Cleanup

Published: Aug 13, 2024 | Modified: Nov 05, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Potential Mitigations

References