CVE-2021-3565 describes a flaw in tpm2-tools versions prior to 5.1.1 and 4.3.2, where the tpm2_import utility used a fixed AES key for its inner wrapper. This vulnerability primarily affects tpm2-tools, Red Hat Enterprise Linux, and Fedora, potentially allowing a Man-in-the-Middle (MITM) attacker to decrypt sensitive key material during import. Rated as MEDIUM severity with a CVSS score of 5.9, the vulnerability has a network attack vector and high attack complexity, as it requires a MITM position. The primary impact is a high risk to data confidentiality, as an attacker could reveal imported keys. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.2CPE matchmatch criteria | cpe:2.3:a:tpm2-tools_project:tpm2-tools:*:*:*:*:*:*:*:* | ||
>= 5.1, < 5.1.1CPE matchmatch criteria | cpe:2.3:a:tpm2-tools_project:tpm2-tools:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
Jun 8, 2021tpm2-tools: fixed AES wrapping key in tpm2_import
May 25, 2021