CVE-2021-43310

CRITICAL

Keylime < 6.3.0 - Authentication Bypass and Remote Code Execution via Key Reset Request

Title source: llm
STIX 2.1

Description

A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.

References (2)

Core 2
Core References
Exploit, Mailing List, Patch, Third Party Advisory x_refsource_misc
https://seclists.org/oss-sec/2022/q1/101
Mitigation, Third Party Advisory x_refsource_misc
https://github.com/keylime/keylime/security/advisories/GHSA-2m39-75g9-ff5r

Scores

CVSS v3 9.8
EPSS 0.0170
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-290
Status published
Products (1)
keylime/keylime < 6.3.0
Published Sep 21, 2022
Tracked Since Feb 18, 2026