CVE-2025-13609: Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.
Other sources
The Keylime registrar allows registration of another agent (different TPM device, different EK certificate) with a duplicate UUID. This presents a critical security vulnerability that allows an attacker to take over an existing agent's identity by re-registering with the same UUID though a different TPM's EK certificate.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/keylimeto a version that resolves this vulnerability.Fixed in 7.13.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13609?
The severity of CVE-2025-13609 is rated as high due to the potential for identity compromise of agents.
How do I fix CVE-2025-13609?
To fix CVE-2025-13609, ensure that agents are registered with their correct Trusted Platform Module (TPM) identifiers and implement access controls.
What are the potential impacts of CVE-2025-13609?
The potential impacts of CVE-2025-13609 include unauthorized access and control over legitimate agent identities in the Keylime system.
Who is affected by CVE-2025-13609?
CVE-2025-13609 affects users of Keylime where agents utilize Trusted Platform Module (TPM) devices for identity verification.
What is the exploitation method for CVE-2025-13609?
CVE-2025-13609 can be exploited by registering a new agent with a different TPM while claiming an existing agent's UUID, thus overwriting its identity.