tpm2-tss是tpm2开源的一个 TCG TPM2 软件堆栈(TSS2)的 OSS 实现。 tpm2-tss 4.0.1及之前版本存在安全漏洞,该漏洞源于JSON结构可以使用任意数字,导致攻击者可因此获得不应有的数据访问权限或服务权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tpm2-software | tpm2-tss | < 4.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-29039 | 9.1 CRITICAL | Missing check in tpm2_checkquote allows attackers to misrepresent the TPM state |
| CVE-2024-29038 | 4.3 MEDIUM | tpm2 does not detect if quote was not generated by TPM |
No comments yet