Lfedge

Eve

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 21.09.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 08:24:30

On boot, the Pillar eve container checks for the existence and content of “/config/GlobalConfig/global.json”. If the file exists, it overrides the existing configuration on the device on boot. This allows an attacker to change the system’s configu...

  • EPSS 0.03%
  • Veröffentlicht 21.09.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 08:24:30

When sealing/unsealing the “vault” key, a list of PCRs is used, which defines which PCRs are used. In a previous project, CYMOTIVE found that the configuration is not protected by the secure boot, and in response Zededa implemented measurements on ...

  • EPSS 0.03%
  • Veröffentlicht 21.09.2023 14:15:11
  • Zuletzt bearbeitet 21.11.2024 08:24:31

Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey" calls "retrieveCloudKey" (which wi...