Database/Firmware, BMC & network fabric
GRUB2 (dump command lockdown): The dump command was not disabled under Secure Boot lockdown, letting a privileged user
CVSS 4.4CVE-2025-1118Firmware, BMC & network fabricGRUB2 2025 batchcurated
Impact
The dump command was not disabled under Secure Boot lockdown, letting a privileged user read arbitrary memory at boot. That includes anything the firmware left in RAM - most usefully, key material and Secure Boot state. Low CVSS, high value as a reconnaissance primitive before a real bypass.
Who can reach it
Local privileged user at the GRUB shell.
What to do
grub2 package update + reboot. A GRUB password limits access to the shell in the meantime, but does not fix the lockdown gap.
References
Related entries
- Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource management: An attackerCVE-2025-12896 · Solidigm DC SSD firmware - unauthorized access to a LOCKED storage device via improper resource managementMedium
- Juniper Junos OS kernel: Improper isolation in the Junos kernel lets a local attacker with shell access injectCVE-2025-21590 · Juniper Junos OS kernelMedium
- Lenovo XClarity Controller (LDAP mode): Read-only authentication bypass when XCC is in LDAP-only authentication modeCVE-2021-3956 · Lenovo XClarity Controller (LDAP mode)Medium
- tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATEDCVE-2024-29040 · tpm2-tss (FAPI quote verification)Medium
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMICVE-2024-8059 · Lenovo XClarity Controller (XCC) - audit logMedium
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userCVE-2025-31938 · Intel Xeon 6 Scalable processors with Intel TDX (subsystem access control)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.