See how opennhp compares to other vendors in security performance
OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a testpurpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the testpurpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.