CVE-2025-13609

EUVD-2025-198980
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
redhatCNA
8.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
keylimekeylime
𝑥
< 7.14.0
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keylime
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
keylime
RHEL 9
0:7.12.1-11.el9_7.3
fixed
keylime-base
RHEL 9
0:7.12.1-11.el9_7.3
fixed
keylime-registrar
RHEL 9
0:7.12.1-11.el9_7.3
fixed
keylime-selinux
RHEL 9
0:7.12.1-11.el9_7.3
fixed
keylime-tenant
RHEL 9
0:7.12.1-11.el9_7.3
fixed
keylime-verifier
RHEL 9
0:7.12.1-11.el9_7.3
fixed
python3-keylime
RHEL 9
0:7.12.1-11.el9_7.3
fixed