Dell Unity: Is Unity affected by CVE-2022-34301 Vulnerability (User Correctable)
Summary: This article details the susceptibility of Dell Unity to the vulnerability detailed in CVE-2022-34301.
Symptoms
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and run arbitrary code in the pre-boot stage, an attacker must simply replace the existing signed bootloader in use with this bootloader. Access to the EFI System Partition is required for booting using external media.
Cause
CVE-2022-34301: NVD - CVE-2022-34301
Resolution
Unity is not affected by CVE-2022-34301.
Unity is using:
Operating System: SUSE Linux Enterprise Server 15
CPE OS Name: cpe:/o:suse:sles:15
Kernel: Linux 4.12.14-150000.150.92.2.NEOKERNEL_SLES15
Architecture: x86-64
From CVE-2022-34301 details:
SUSE Linux Enterprise Server 15 >>>> Not affected
Check CVE details:
https://www.suse.com/security/cve/CVE-2022-34301.html