← Back

CVE-2021-38576

nvd nist
Published: Jan 3, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Affected (12)

Products: Tianocore: Edk2
1 product
Edk2
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Tianocore
Version 201808
Version 201811
Version 201903
Version 201905
Version 201908
Version 201911
Version 202002
Version 202005
Version 202008
Version 202011
Version 202102
Version 202105

References (3)

Source: infosec@edk2.groups.io
Issue TrackingPermissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.