CVE-2021-43310
Published on: Not Yet Published
Last Modified on: 12/21/2022 03:01:00 PM UTC
Certain versions of Keylime from Keylime contain the following vulnerability:
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.
- CVE-2021-43310 has been assigned by
patrick@puiterwijk.org to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Keylime: malicious reset or replay of U and V encryption · Advisory · keylime/keylime · GitHub | github.com text/html |
![]() |
oss-sec: keylime: Multiple Security Issues (including remote code execution in the Agent component) | seclists.org text/html |
![]() |
Related QID Numbers
Exploit/POC from Github
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V ke…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Keylime | Keylime | All | All | All | All |
- cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Keylime code execution | CVE-2021-43310 - redpacketsecurity.com/keylime-code-e… | 2022-01-31 11:02:28 |
![]() |
Vigil@nce #Vulnérabilité de Keylime : six vulnérabilités. vigilance.fr/vulnerabilite/… Références : #CVE-2021-43310,… twitter.com/i/web/status/1… | 2022-02-04 10:09:08 |
![]() |
Vigil@nce #Vulnerability of Keylime: six vulnerabilities. vigilance.fr/vulnerability/… Identifiers: #CVE-2021-43310,… twitter.com/i/web/status/1… | 2022-02-04 10:09:09 |
![]() |
CVE-2021-43310 : A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that re… twitter.com/i/web/status/1… | 2022-09-21 19:09:29 |
![]() |
New vulnerability on the NVD: CVE-2021-43310 ift.tt/qKd6BUW | 2022-09-21 20:16:50 |
![]() |
New vulnerability on the NVD: CVE-2021-43310 ift.tt/sfdF2Yq | 2022-09-21 20:33:24 |
![]() |
New vulnerability on the NVD: CVE-2021-43310 ift.tt/wHgDjs5 | 2022-09-21 20:40:30 |
![]() |
CVE-2021-43310 ift.tt/3u46NZY | 2022-09-21 20:52:47 |
![]() |
CVE-2021-43310 | 2022-09-21 20:38:52 |