Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29038


tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.


Published

2024-06-28T14:15:03.033

Last Modified

2025-10-22T20:39:37.057

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-1283
    CWE-1390

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tpm2-tools_project tpm2-tools < 5.5.1 Yes
Application tpm2-tools_project tpm2-tools < 5.7 Yes

References