Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-29039


tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. As a result, digest values are incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. This issue has been patched in version 5.7.


Published

2024-06-28T16:15:03.777

Last Modified

2025-10-02T14:15:24.910

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-807

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tpm2-tools_project tpm2-tools < 5.7 Yes

References