Описание
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.
Ссылки
- MitigationThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
- MitigationThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.3.0 (исключая)
cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02758
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-290
CWE-290
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 3 лет назад
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.
EPSS
Процентиль: 86%
0.02758
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-290
CWE-290