CVE-2023-3674CWE-1283

Keylime: attestation failure when the quote's signature does not validate

Low · published July 19, 2023

CVSS v3.1
2.3
EPSS
0%
Percentile
11.6
In the wild
Unconfirmed
What it is

A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.

The record
Technical detail
CVSS v3.1
2.3 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00214 · 11.6th percentile
Weakness
CWE-1283 · Mutable Attestation or Measurement Reporting Data
Published
2023-07-19T18:25Z
EPSS history
Timeline
  • 19 JUL 18:25Z
    Keylime: attestation failure when the quote's signature does not validate
    cvelistv5