CVE-2017-7524Insufficiently Protected Credentials in Tpm2-tools

Severity
7.5HIGHNVD
EPSS
0.2%
top 51.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 13

Description

tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/tpm2-tools< tpm2-tools 2.1.0-1 (bookworm)
Debiantpm2-tools_project/tpm2-tools< 2.1.0-1+3
CVEListV5tpm_2.0_tools/tpm2-toolsbefore 1.1.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-62m4-8mv5-x4gc: tpm2-tools versions before 12022-05-13
OSV
CVE-2017-7524: tpm2-tools versions before 12017-06-27

📋Vendor Advisories

2
Red Hat
tpm2-tools: Sending password in plaintext for HMAC generation on server2017-06-21
Debian
CVE-2017-7524: tpm2-tools - tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transm...2017

💬Community

3
Bugzilla
CVE-2017-7524 tpm2-tools: Sending password in plaintext for HMAC generation on server [epel-7]2017-06-27
Bugzilla
CVE-2017-7524 tpm2-tools: Sending password in plaintext for HMAC generation on server [fedora-all]2017-06-27
Bugzilla
CVE-2017-7524 tpm2-tools: Sending password in plaintext for HMAC generation on server2017-06-27