Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-13609

30
FAUCET Score

CVE-2025-13609 describes a high-severity vulnerability in Keylime, where an attacker can impersonate an existing agent by registering a new TPM device with a legitimate agent's unique identifier, overwriting its identity. This allows the attacker to bypass security controls and potentially compromise the system. The vulnerability has a CVSS score of 8.2 (HIGH) due to its network attack vector, low attack complexity, and high impact on integrity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.2 Update Services For SAP Solutions
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 10
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 12th percentile among its peer group of 5,531 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

pippatch availablevia ghsa
Product: keylimeFixed in: 7.13.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: keylime-0:7.12.1-11.el10_1.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: keylime-0:7.12.1-2.el10_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: keylime-0:7.12.1-11.el9_7.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: keylime-0:6.5.2-6.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: keylime-0:7.3.0-13.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: keylime-0:7.3.0-15.el9_6.1
View patch

Vendor Advisories (2)

pipGHSA-xh5w-g8gq-r3v9high

Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices

Nov 24, 2025
redhatCVE-2025-13609Important

keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration

Nov 24, 2025

References

access.redhat.com / errata/RHSA-2025:23201
access.redhat.com / errata/RHSA-2025:23210
access.redhat.com / errata/RHSA-2025:23628
access.redhat.com / errata/RHSA-2025:23735
access.redhat.com / errata/RHSA-2025:23852
access.redhat.com / errata/RHSA-2026:0429
access.redhat.com / security/cve/CVE-2025-13609
bugzilla.redhat.com / show_bug.cgi
github.com / keylime/keylime/issues/1820