CVE-2022-1053 is a critical vulnerability in Keylime and Fedora Keylime that allows an attacker to bypass critical security checks by manipulating agent registration data. Specifically, Keylime fails to enforce consistent agent registrar data between the tenant's EK/identity quote validation and the verifier's integrity quote validation. This enables an attacker to substitute a software TPM's Attestation Key (AK) after initial validation, breaking the entire chain of trust. With a CVSS score of 9.1 (Critical), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction. A successful exploit could lead to high confidentiality and integrity impacts, as an unvalidated AK is used by the verifier, compromising the system's trustworthiness. Currently, there is no public exploit intelligence available, such as Metasploit modules or ExploitDB entries, and it is not listed on the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or active exploitation at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.0CPE matchmatch criteria | cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.