CVE-2021-43310
21.09.2022, 19:15
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| keylime | keylime | 𝑥 < 6.3.0 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| keylime-agent |
| ||||||||||||||||||||||||
| keylime-config |
| ||||||||||||||||||||||||
| keylime-firewalld |
| ||||||||||||||||||||||||
| keylime-logrotate |
| ||||||||||||||||||||||||
| keylime-registrar |
| ||||||||||||||||||||||||
| keylime-tpm_cert_store |
| ||||||||||||||||||||||||
| keylime-verifier |
| ||||||||||||||||||||||||
| python3-keylime |
|
Common Weakness Enumeration