CVE-2023-3674

A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.3 LOW
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
keylimekeylime
𝑥
< 7.2.5
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
keylime
RHEL 9
0:7.3.0-13.el9_3
fixed
keylime-base
RHEL 9
0:7.3.0-13.el9_3
fixed
keylime-registrar
RHEL 9
0:7.3.0-13.el9_3
fixed
keylime-selinux
RHEL 9
0:7.3.0-13.el9_3
fixed
keylime-tenant
RHEL 9
0:7.3.0-13.el9_3
fixed
keylime-verifier
RHEL 9
0:7.3.0-13.el9_3
fixed
python3-keylime
RHEL 9
0:7.3.0-13.el9_3
fixed