CVE-2021-43310: Critical severity keylime (keylime) vulnerability
Published Sep 21, 2022
·Updated
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.
Affected Software
1 affected component
Keylime Keylime<6.3.0
Remediation
Patch Available
Event History
Sep 21, 2022
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-43310.
2
What is the severity level of CVE-2021-43310?
The severity level of CVE-2021-43310 is critical.
3
What is the affected software version of CVE-2021-43310?
The affected software version of CVE-2021-43310 is Keylime before 6.3.0.
4
How does CVE-2021-43310 impact the system?
CVE-2021-43310 allows an attacker to reset the U and V keys, potentially leading to remote code execution.
5
Where can I find more information about CVE-2021-43310?
You can find more information about CVE-2021-43310 at the following references: [link 1](https://github.com/keylime/keylime/security/advisories/GHSA-2m39-75g9-ff5r) and [link 2](https://seclists.org/oss-sec/2022/q1/101).