CVE-2019-14560: Medium severity Tianocore edk2 vulnerability
REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
Other sources
A flaw was found in edk2. Function GetEfiGlobalVariable2() return value is not checked possibly leading to secure boot bypass if an attacker can cause the API to fail.
References:
https://bugzilla.tianocore.org/showbug.cgi?id=2167
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14560?
CVE-2019-14560 has been marked as REJECTED and does not have an assigned severity due to lack of documented issues.
What systems are affected by CVE-2019-14560?
CVE-2019-14560 potentially impacts the TianoCore edk2, although this candidate was ultimately not assigned.
How do I mitigate CVE-2019-14560?
Since CVE-2019-14560 was not assigned to any specific issue, there are no mitigation steps necessary for this candidate.
Is CVE-2019-14560 exploitable?
CVE-2019-14560 is not exploitable as it was never confirmed to have any vulnerabilities due to its REJECTED status.
Where can I find more information about CVE-2019-14560?
Information about CVE-2019-14560 is limited as the candidate was not assigned to any issues.