PT-2025-47950 · Keylime+3 · Keylime+3
Published
2025-11-24
·
Updated
2026-03-20
·
CVE-2025-13609
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
keylime (affected versions not specified)
Description
A flaw exists in keylime that allows an attacker to register a new agent using a different Trusted Platform Module (TPM) device while claiming an existing agent’s unique identifier (UUID). This overwrites the legitimate agent's identity, potentially enabling the attacker to impersonate the compromised agent and bypass security controls.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Red Hat
Rocky Linux
Keylime