PT-2023-26334 · Keylime+3 · Keylime+3

Florian Kohnhäuser

+1

·

Published

2023-08-25

·

Updated

2024-09-16

·

CVE-2023-38201

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Keylime versions prior to 7.5.0
Description A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database. The security issue allows an attacker to pass the challenge-response protocol during registration with arbitrary registration data, including a valid EK Certificate and EK, while using a compromised AIK. The attacker can deliberately fail the initial activation call to get to know the correct auth tag and then provide it in a subsequent activation call, resulting in an agent which is incorrectly registered with a valid EK Certificate, but with a compromised/unrelated AIK.
Recommendations For versions prior to 7.5.0, users should upgrade to release 7.5.0 to resolve the issue. As a temporary workaround, consider restricting access to the registrar to minimize the risk of exploitation. Avoid using compromised AIKs in the registration process until the issue is resolved.

Fix

IDOR

Weakness Enumeration

Related Identifiers

ALSA-2023:5080
CVE-2023-38201
GHSA-F4R5-Q63F-GCWW
OPENSUSE-SU-2023_3525-1
OPENSUSE-SU-2024:13287-1
PYSEC-2023-160
RHSA-2023:5080
RHSA-2023_5080
SUSE-SU-2023:3525-1
SUSE-SU-2023_3525-1

Affected Products

Almalinux
Keylime
Red Hat
Suse