Vulnerabilities > CVE-2020-15780 - Missing Authorization vulnerability in multiple products

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
linux
opensuse
canonical
CWE-862

Summary

An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.

Vulnerable Configurations

Part Description Count
OS
Linux
3579
OS
Opensuse
2
OS
Canonical
3

Common Weakness Enumeration (CWE)