VYPR

CWE-1291

Public Key Re-Use for Signing both Debug and Production Code

BaseDraft

Description

The same public key is used for signing both debug and production code.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (1)

  • CVE-2022-1665HigJun 21, 2022
    risk 0.53cvss 8.2epss 0.00

    A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot…