PT-2026-6461 · Go · Github.Com/Lf-Edge/Eve

Published

2026-02-04

·

Updated

2026-02-04

CVSS v3.1

5.2

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Impact

PCR14 is not included in the list of PCRs that seal/unseal the vault key. Additionally, the vault key uses SHA1 PCRs instead of SHA256. Thus an attacker with physical access can take out the disk, use a different computer to modify the files in the /config partition, and re-insert the disk and boot without the change being detected by measured boot and remote attestation.

Patches

Fixed in EVE version 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Resources

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

GHSA-PHCG-H58R-GMCQ

Affected Products

Github.Com/Lf-Edge/Eve