CVE-2024-29038
tpm2 does not detect if quote was not generated by TPM
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
tpm2-tools es el repositorio de origen de las herramientas del Módulo de plataforma segura (TPM2.0). Un atacante malintencionado puede generar datos de cotizaciones arbitrarios que no son detectados por "tpm2 checkquote". Este problema se solucionó en la versión 5.7.
A flaw was found in the tpm2-tools package. This issue occurs due to a missing check whether the magic number in attest is equal to TPM2_GENERATED_VALUE, which can allow an attacker to generate arbitrary quote data that may not be detected by tpm2_checkquote.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-03-14 CVE Reserved
- 2024-06-28 CVE Published
- 2024-06-29 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-1283: Mutable Attestation or Measurement Reporting Data
- CWE-1390: Weak Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/tpm2-software/tpm2-tools/releases/tag/5.7 | X_refsource_misc | |
https://github.com/tpm2-software/tpm2-tools/security/advisories/GHSA-5495-c38w-gr6f | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2024-29038 | 2024-11-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2278071 | 2024-11-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tpm2-software Search vendor "Tpm2-software" | Tpm2-tools Search vendor "Tpm2-software" for product "Tpm2-tools" | >= 4.1 < 5.7 Search vendor "Tpm2-software" for product "Tpm2-tools" and version " >= 4.1 < 5.7" | en |
Affected
|