CWE-1283Base

Mutable Attestation or Measurement Reporting Data

Incomplete in the CWE catalog · 3 CVEs mapped

3
CVEs mapped
4.3
Median CVSS
What it is

The register contents used for attestation or measurement reporting data to verify boot flow are modifiable by an adversary.

Recent examples
4.3cvss
CVE-2024-29038

tpm2 does not detect if quote was not generated by TPM

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

MEDIUMno explanation yet
0%
epss
2.3cvss
CVE-2023-3674

Keylime: attestation failure when the quote's signature does not validate

A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.

LOWno explanation yet
0%
epss
4.6cvss
CVE-2022-1740

2.2.2 MUTABLE ATTESTATION OR MEASUREMENT REPORTING DATA CWE-1283

The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export, and application export functionality rely on self-attestation mechanisms. An attacker could leverage this vulnerability to disguise malicious applications on a device.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1283
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)