Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-1053

24
FAUCET Score

CVE-2022-1053 is a critical vulnerability in Keylime and Fedora Keylime that allows an attacker to bypass critical security checks by manipulating agent registration data. Specifically, Keylime fails to enforce consistent agent registrar data between the tenant's EK/identity quote validation and the verifier's integrity quote validation. This enables an attacker to substitute a software TPM's Attestation Key (AK) after initial validation, breaking the entire chain of trust. With a CVSS score of 9.1 (Critical), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction. A successful exploit could lead to high confidentiality and integrity impacts, as an unvalidated AK is used by the verifier, compromising the system's trustworthiness. Currently, there is no public exploit intelligence available, such as Metasploit modules or ExploitDB entries, and it is not listed on the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness or active exploitation at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.4.0CPE matchmatch criteria
cpe:2.3:a:keylime:keylime:*:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.39%
Probability of exploitation in next 30 days
EPSS Percentile
69.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0139 is in the 56th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: keylimeFixed in: 6.4.0

Vendor Advisories (1)

pipGHSA-jf66-3q76-h5p5critical

Tenant and Verifier might not use the same registrar data

May 5, 2022

References

bugzilla.redhat.com / show_bug.cgi
github.com / keylime/keylime/commit/bd5de712acdd77860e7dc58969181e16c7a8dc5d
PatchThird Party Advisory
github.com / keylime/keylime/security/advisories/GHSA-jf66-3q76-h5p5%2C
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/A7WAKVXM7L5D2DUACV6EHA6EJNAX2GVL
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/RF6QHU4UGSBATC3HOOE7OP66CYVTR7CV
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WEW2PAXO5YGLDLPG45YV2OPLJXJSCECQ