cbcvebase.
CVE-2024-29038
published 2024-06-28

CVE-2024-29038: tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not…

PriorityP414low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.37%
29.7th percentile
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiantpm2-tools< tpm2-tools 5.7-1 (forky)tpm2-tools 5.7-1 (forky)
msrcazl3_tpm2-tools_5.5.1-1_on_azure_linux_3.0
msrccbl2_tpm2-tools_4.3.2-2_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
tpm2-softwaretpm2-tools
tpm2-tools_projecttpm2-tools< 5.75.7
tpm2-tools_projecttpm2-tools>= 0 < 5.7-15.7-1
tpm2-tools_projecttpm2-tools>= 0 < 5.7-15.7-1
tpm2-tools_projecttpm2-tools>= 4.1 < 5.5.15.5.1

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.