Security Advisory

CVE-2021-3565

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-06-04 11:39:40
Last updated 2024-08-03 17:01:07
Assigner redhat
State PUBLISHED

Description

A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.