CVE-2021-38576: High severity tianocore edk ii vulnerability
Published Jan 3, 2022
·Updated
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
Affected Software
12 affected components
Tianocore edk2=201808
Tianocore edk2=201811
Tianocore edk2=201903
Tianocore edk2=201905
Tianocore edk2=201908
Tianocore edk2=201911
Tianocore edk2=202002
Tianocore edk2=202005
Tianocore edk2=202008
Tianocore edk2=202011
Tianocore edk2=202102
Tianocore edk2=202105
Event History
Jan 3, 2022
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this BIOS bug?
The vulnerability ID for this BIOS bug is CVE-2021-38576.
2
What is the severity level of CVE-2021-38576?
The severity level of CVE-2021-38576 is high with a CVSS score of 7.5.
3
How does this BIOS bug affect the system?
This BIOS bug can be used to permanently brick the TPM in multiple ways and can also non-permanently DoS the system.
4
Which PC models are affected by this BIOS bug?
This BIOS bug affects a particular PC model.
5
Is there a fix available for CVE-2021-38576?
Please refer to the reference link for information on available fixes for CVE-2021-38576.