Back

MEDIUM

tpm2-tools: fixed AES wrapping key in tpm2_import

Published Jun 4, 2021

Description

A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 7 is not affected by this issue, as it ships an older version of `tpm2-tools` which does not include the tpm2_import tool.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jun 4, 2021
Updated Aug 3, 2024
Reserved May 25, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 25, 2021
Bugzilla 1964427

ENISA EUVD

Assigner redhat
Published Jun 4, 2021
Updated Aug 3, 2024

GitHub

No data