Boot Guard cannot be trusted on multiple Clevo-based devices (the private RSA keys for the Key Manifest and Boot Policy Manifest has been leaked)
BINARLY REsearch team has received information that Clevo firmware update packages are being distributed with private keys for Boot Guard: https://github.com/binarly-io/SupplyChainAttacks/issues/6. The Binarly REsearch team checked an internal dataset of firmware images for the use of leaked keys across different vendors and discovered several affected devices, some of which had received updates only a few months ago.
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks, and chart a path to post-quantum readiness.
Potential Impact
The Boot Guard hardening technology in the firmware of affected devices cannot be trusted because the private RSA key for the Key Manifest and Boot Policy Manifest has been leaked. This means that an attacker with write access to the SPI flash storage (e.g. by physical access or by exploiting a BIOS write protection bypass vulnerability) could install a persistent backdoor/implant.
Image preview
Vulnerability Information
- BINARLY internal identifier: BRLY-2025-002
- CVSS v3.1 Score 7.6 High AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks with reachability and exploitation maturity scoring, and chart a measurable path to post-quantum readiness.