SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20319

An improper signature verification vulnerability was found in coreos-installer.

HIGH 7.8EPSS 0.52%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.52% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-347
Affected
redhat/coreos-installer
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.