CVE-2023-4001: Grub2: bypass the grub password protection feature
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boot/" file system) can bypass the GRUB password protection feature on UEFI systems, which enumerate removable drives before non-removable ones. This issue was introduced in a downstream patch in Red Hat's version of grub2 and does not affect the upstream package.
Other sources
https://bugzilla.redhat.com/showbug.cgi?id=2223437
The "/boot/efi/EFI/fedora/grub.cfg" configuration file allows an unprivileged user with physical access to a computer to bypass the GRUB password protection feature on many (but not all) UEFI-based systems.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2023-4001?
CVE-2023-4001 allows an unprivileged user with physical access to bypass the GRUB password protection.
What versions are affected by CVE-2023-4001?
CVE-2023-4001 affects GRUB2 and specific versions of Red Hat Enterprise Linux 9.0, Fedora 38, and Fedora 39.
How can I mitigate CVE-2023-4001?
To mitigate CVE-2023-4001, restrict physical access to servers and update your GRUB configuration file to strengthen security.
Is CVE-2023-4001 easy to exploit?
Yes, CVE-2023-4001 is considered easy to exploit because it requires only physical access to the machine.
Are there any updates available for CVE-2023-4001?
Yes, patches and updates addressing CVE-2023-4001 have been released and should be applied promptly.