Ask the Community
Groups
CVE-2015-8370: grub2 authentication bypass - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="cve-id"><strong>CVE ID</strong></h3> <p>CVE-2015-8370</p> <h3 data-id="description"><strong>DESCRIPTION</strong></h3> <p>A flaw was found in the way grub2 handled backspace characters entered in username and password prompts. An attacker with access to the system console could use this flaw to bypass grub2 password protection and gain administrative access to the system.<br><br>Unitrends risk assessment: None<br><br>Unitrends systems do not use grub2, but grub-0.97-93.el6.x86_64 or grub-0.97-99 for el5, which are not affected.</p> <h3 data-id="resolution"><strong>RESOLUTION</strong></h3> <p>No action required.</p> <h3 data-id="link-to-advisories"><strong>LINK TO ADVISORIES</strong></h3> <p></p> <ul><li><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2Fcve-2015-8370%250D%250Ahttps%3A%2F%2Frhn.redhat.com%2Ferrata%2FRHSA-2015-2623.html">https://access.redhat.com/security/cve/cve-2015-8370 https://rhn.redhat.com/errata/RHSA-2015-2623.html</a></li> <li><a rel="nofollow" href="(fix">(fix</a></li> <li><a rel="nofollow" href="for">for</a></li> <li><a rel="nofollow" href="el7)%0D%0A/home/leaving?allowTrusted=1&target=http%3A%2F%2Fhmarco.org%2Fbugs%2FCVE-2015-8370-Grub2-authentication-bypass.html">el7) http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html</a></li> </ul> </article> </main>