Remote Attestation TLS(RA-TLS)客户端提供了多种语言的实用工具,用于验证经过远程证明的 TLS 连接。在版本 0.5.0 之前,Rust 和 Go 语言的 RA-TLS 挑战验证器在接受.quote 报告数据(ReportData)时,仅将其与证书公钥和客户端非确定性值(nonce)绑定,而未将其与当前活跃的 TLS 会话绑定,便允许应用流量通过。如果攻击者获取了某个 enclave(可信执行环境)的 TLS 私钥,便可以将一个真实的证明(quote)中继到另一个连接上,从而导致客户端错
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Privasys | ra-tls-clients | < 0.5.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Privasys | ra-tls-clients | < 0.5.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108265 | 9.1 CRITICAL | enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session |
| CVE-2026-108266 | 9.1 CRITICAL | Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s |
| CVE-2026-108267 | 9.1 CRITICAL | Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sessi |
| CVE-2026-108268 | 9.1 CRITICAL | enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session |
No comments yet