VYPR
Medium severity6.7NVD Advisory· Published Feb 14, 2024· Updated Jun 17, 2026

CVE-2023-48733

CVE-2023-48733

Description

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Canonical/Lxd3 versions
    cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:canonical:lxd:5.0:candidate:*:*:*:*:*:*
    • cpe:2.3:a:canonical:lxd:5.21:candidate:*:*:*:*:*:*
    • cpe:2.3:a:canonical:lxd:5.21:edge:*:*:*:*:*:*
  • cpe:2.3:a:tianocore:edk2:*:-:*:*:*:*:*:*
    Range: <=2023.11-8
  • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • Ubuntu/edk2llm-fuzzy
  • Canonical Ltd./Ubuntu EDK IIv5
    Range: 0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.