Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-48733

Published: February 15, 2024Last modified: June 17, 2025

Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Severity score breakdown

ParameterValue
Base score6.7
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSedk2Unknown (0.0.202208-r0)
Streamedk2Unknown (0.0.202302-r0)

References

ON THIS PAGE