VulnerabilityModified
CVE-2021-3406
A flaw was found in keylime 5.8.1 and older.
CRITICAL 9.8EPSS 0.66%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347, CWE-295
- Affected
- keylime/keylime · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1932469Issue Tracking, Third Party Advisory
- https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375mThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/
- https://bugzilla.redhat.com/show_bug.cgi?id=1932469Issue Tracking, Third Party Advisory
- https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375mThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.