Swtpm Project maintains a software TPM (Trusted Platform Module) emulator used in virtualization and testing contexts, with a narrow but structurally important footprint in platforms that simulate trusted hardware. The documented vulnerability pattern centers on file-handling issues, particularly link-following conditions and out-of-bounds reads, which reflect the low-level access and file-system operations inherent to TPM state management. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Swtpm Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28407HIGH In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall. | Nov 3, 2023 | 7.1 | 21 | NO | NO |
CVE-2022-23645MEDIUM swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A spe | Feb 18, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Swtpm Project.
Media articles that mention a CVE ID that affects a product developed by Swtpm Project — matched by CVE ID, not by vendor name.