Insufficient verification of data authenticity in Shim - CVE-2023-40547

 

Insufficient verification of data authenticity in Shim - CVE-2023-40547

Published: February 7, 2024


Vulnerability identifier: #VU86236
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-40547
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing verification of data authenticity when parsing HTTP responses. A remote attacker can perform a man-in-the-middle (MitM) attack and use a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise.

This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.


Affected software

Shim
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
openEuler
Microsoft Windows
Windows Server
Juniper Secure Analytics (JSA)
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
IBM Power Hardware Management Console (HMC)
IBM Qradar SIEM
Dell EMC VxRail Appliance
RSA Authentication Manager
shim
shim-debugsource
shim-debuginfo
shim-aa64
shim-x64
shim-signed (Red Hat package)
shim-ia32
mokutil
shim (Red Hat package)
shim-unsigned-x64 (Red Hat package)
shim-unsigned-aarch64 (Red Hat package)
shim-unsigned-x64
shim-unsigned-ia32

How to mitigate CVE-2023-40547

Install updates from vendor's website.

Shim - update to 15.8
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF03
Dell EMC VxRail Appliance - update to 8.0.212
RSA Authentication Manager - update to 8.7 SP2 Patch 2
Microsoft Windows - addressed in versions 10 21H2 10.0.19044.4780, 10 22H2 10.0.19045.4529, 10 22H2 10.0.19045.4780, 10 1507 10.0.10240.20751, 10 1607 10.0.14393.7259, 10 1809 10.0.17763.6189, 11 21H2 10.0.22000.3147, 11 22H2 10.0.22621.4037, 11 23H2 10.0.22631.4037
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP2, 10.3.1060.0
shim - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19, 15-28, 15-34
shim-debugsource - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19, 15-28, 15-34
shim-debuginfo - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19, 15-28, 15-34
shim-aa64 - addressed in versions 15.7-3, 15.8-1.0.1, 15.8-2.0.1
shim-x64 - addressed in versions 15.7-3, 15.8-1.0.1, 15.8-2.0.1
shim-signed (Red Hat package) - update to 15.8-1.el7
shim-ia32 - addressed in versions 15.8-1.0.1, 15.8-2.0.1
mokutil - update to 15.8-1.0.1
shim (Red Hat package) - addressed in versions 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3
shim-unsigned-x64 (Red Hat package) - addressed in versions 15.8-2.el8, 15.8-2.el9
shim-unsigned-aarch64 (Red Hat package) - update to 15.8-2.el9
shim-unsigned-x64 - addressed in versions 15.8-2.0.1, 15.8-3.0.1
shim-unsigned-ia32 - update to 15.8-3.0.1
shim - addressed in versions 15.8-25.30.1, 15.8-150100.3.38.1
shim-debugsource - update to 15.8-150100.3.38.1
shim-debuginfo - update to 15.8-150100.3.38.1
Windows Server - addressed in versions 2012 R2 6.3.9600.22134, 2012 6.2.9200.25031, 2016 10.0.14393.7259, 2022 10.0.20348.2655

External References

Related Security Bulletins