Contrast 版本低于 1.16.0 的系统容易受到远程认证中继攻击。Contrast 接受任何经过正确验证且包含预期固件补丁级别和软件测量值的 TEE(可信执行环境)认证报告,而不论该报告由哪台机器生成,因此认证过程未绑定到特定的、物理上可信的硬件。如果攻击者能够拦截 CLI(命令行接口)与协调器(Coordinator)之间(或协调器与已认证的组件之间)的网络流量,并且能够伪造报告或从其物理控制的任意一台 TEE 机器中提取密钥,那么攻击者就可以将此类报告中继转发,从而冒充 Contrast 协调器或 Co
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 0 ~ 1.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100839 | 8.4 HIGH | Contrast before 1.18.0 AML Injection Remote Code Execution |
| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100838 | 8.1 HIGH | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71423 | 7.3 HIGH | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100836 | 4.3 MEDIUM | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer |
| CVE-2026-100837 | 3.7 LOW | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet