IGEL OS 12 12.9.0 之前版本、12.8.3 LTS 以及 IGEL OS 11 11.11.150 之前版本中存在一个安全启动绕过漏洞,位于 GRUB 引导阶段。该漏洞允许物理接触设备的攻击者通过将名为 的未签名空文件放置到某个分区上,从而获得未经授权的 root 权限。 攻击者可利用 GRUB 在签名验证失败时采取“失败即开放”(fail-open)的特性,进入交互式 GRUB 命令行提示符,然后使用设备自身的内核并附加额外的命令行参数进行引导,从而在保持磁盘解锁状态且 TPM PCR 值未被修改
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IGEL | IGEL OS 12 | 12.0.0 ~ 12.8.2 | - |
|
| IGEL | IGEL OS 11 | 11.0.0 ~ 11.11.150 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet