Lucene search

K
redhatcveRedhat.comRH:CVE-2024-29039
HistoryMay 01, 2024 - 1:59 a.m.

CVE-2024-29039

2024-05-0101:59:20
redhat.com
access.redhat.com
8
cve-2024-29039
security vulnerability

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.1%

A flaw was found in tpm2-tools. The PCR selection, which is passed with the --pcr parameter, is not compared with the attest, making it possible for an attacker to fake a valid attestation.

CVSS3

9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.1%