CVE-2009-4128
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- gnu/grub 2
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195Exploit
- http://www.openwall.com/lists/oss-security/2024/01/15/3
- http://www.securityfocus.com/bid/36968Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54210
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195Exploit
- http://www.openwall.com/lists/oss-security/2024/01/15/3
- http://www.securityfocus.com/bid/36968Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54210
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.