CVE-2023-3674 - CERT CVE
ID CVE-2023-3674
Sažetak A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
Reference
CVSS
Base: 2.8
Impact: 1.4
Exploitability:1.3
Pristup
VektorSloženostAutentikacija
LOCAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Zadnje važnije ažuriranje 25-04-2024 - 13:15
Objavljeno 19-07-2023 - 19:15