SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2023-5342

The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.

MEDIUM 4.1EPSS 0.08%

Does this matter?

Lower severity and a low EPSS score (0.08%). Track it; it rarely justifies an emergency change on its own.

Description

The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.

CVSS 3.1
4.1 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS
0.08% probability · 0th percentile
CISA KEV
Not listed
Weakness
CWE-324
Source
patrick@puiterwijk.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.