CVE-2023-22745 is a buffer overrun vulnerability in tpm2-tss, an open-source Trusted Platform Module (TPM) 2 Software Stack, affecting versions prior to 4.1.0-rc0, 4.0.1, and 3.2.2-rc1. The vulnerability, rated Medium (CVSS 6.4), allows for arbitrary code execution due to improper indexing in Tss2_RC_SetHandler and Tss2_RC_Decode functions. Exploitation requires local system privileges and a Man-in-the-Middle (MiTM) bus attack, making it a high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.2CPE matchmatch criteria | cpe:2.3:a:tpm2_software_stack_project:tpm2_software_stack:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.1.0CPE matchmatch criteria | cpe:2.3:a:tpm2_software_stack_project:tpm2_software_stack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024tpm2-tss: Buffer Overlow in TSS2_RC_Decode
Jan 20, 2023Buffer Overlow in TSS2_RC_Decode in tpm2-tss
Jan 10, 2023