{"api_version":"1","generated_at":"2026-04-23T03:26:04+00:00","cve":"CVE-2021-3406","urls":{"html":"https://cve.report/CVE-2021-3406","api":"https://cve.report/api/cve/CVE-2021-3406.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-3406","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-3406"},"summary":{"title":"CVE-2021-3406","description":"A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-02-25 20:15:00","updated_at":"2023-11-07 03:37:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1932469","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1932469","refsource":"MISC","tags":["Issue Tracking","Third Party Advisory"],"title":"1932469 – (CVE-2021-3406) CVE-2021-3406 keylime: Key cryptographic chain of trust breakage","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m","name":"https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m","refsource":"MISC","tags":["Third Party Advisory"],"title":"Key cryptographic chain of trust breakage · Advisory · keylime/keylime · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/","name":"FEDORA-2021-b7854ccfe4","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: keylime-6.0.0-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/","name":"FEDORA-2021-b7854ccfe4","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: keylime-6.0.0-1.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-3406","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3406","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"3406","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3406","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3406","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"3406","vulnerable":"1","versionEndIncluding":"5.8.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"keylime","cpe5":"keylime","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-3406","qid":"281595","title":"Fedora Security Update for keylime (FEDORA-2021-b7854ccfe4)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-3406","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"keylime","version":{"version_data":[{"version_value":"5.8.1 and older"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-347"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1932469","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1932469"},{"refsource":"MISC","name":"https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m","url":"https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m"},{"refsource":"FEDORA","name":"FEDORA-2021-b7854ccfe4","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations."}]}},"nvd":{"publishedDate":"2021-02-25 20:15:00","lastModifiedDate":"2023-11-07 03:37:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:*","versionEndIncluding":"5.8.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"3406","Ordinal":"202023","Title":"CVE-2021-3406","CVE":"CVE-2021-3406","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"3406","Ordinal":"1","NoteData":"A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"3406","Ordinal":"2","NoteData":"2021-02-25","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"3406","Ordinal":"3","NoteData":"2021-03-19","Type":"Other","Title":"Modified"}]}}}