CVE-2023-38201

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
keylimekeylime
𝑥
< 7.5.0
redhatenterprise_linux
9.0
redhatenterprise_linux_eus
9.2
redhatenterprise_linux_for_ibm_z_systems
9.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems_eus
9.2_s390x:_s390x
redhatenterprise_linux_for_power_little_endian
9.0_ppc64le:_ppc64le
redhatenterprise_linux_for_power_little_endian_eus
9.2_ppc64le:_ppc64le
redhatenterprise_linux_server_aus
9.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keylime
bionic
ignored
focal
dne
jammy
dne
lunar
dne
trusty
ignored
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
keylime
RHEL 9
0:6.5.2-6.el9_2
fixed
keylime-base
RHEL 9
0:6.5.2-6.el9_2
fixed
keylime-registrar
RHEL 9
0:6.5.2-6.el9_2
fixed
keylime-selinux
RHEL 9
0:6.5.2-6.el9_2
fixed
keylime-tenant
RHEL 9
0:6.5.2-6.el9_2
fixed
keylime-verifier
RHEL 9
0:6.5.2-6.el9_2
fixed
python3-keylime
RHEL 9
0:6.5.2-6.el9_2
fixed