CVE Vulnerabilities

CVE-2024-7344

Improper Verification of Cryptographic Signature

Published: Jan 14, 2025 | Modified: Jan 21, 2025
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Howyar UEFI Application Reloader (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Neo_impact Cs-grp * 10.1.024-20241127 (excluding)
Greenguard Greenware * 10.2.023-20240927 (excluding)
Sysreturn Howyar * 10.2.023_20240919 (excluding)
Smart_recovery Radix * 11.2.023-20240927 (excluding)
Ez-back_system Sanfong * 10.3.024-20241127 (excluding)
Hdd_king Signalcomputer * 10.3.021-20241127 (excluding)
Erecoveryrx Wasay * 8.4.022-20241127 (excluding)

References