The Trousers Project maintains a specialized TPM (Trusted Platform Module) software stack, a narrowly scoped library that serves as the interface layer between applications and hardware security modules used in enterprise and government systems. Its documented exposure centers on the core Trousers product and recurs through improper privilege-management weaknesses that reflect the access-control boundaries inherent to TPM interaction. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trousers Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24331HIGH An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (whi | Aug 13, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-24330HIGH An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no l | Aug 13, 2020 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trousers Project.
Media articles that mention a CVE ID that affects a product developed by Trousers Project — matched by CVE ID, not by vendor name.