Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

GHSA-5jvg-8j6f-vpmc

Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts
Back to all
CVE

GHSA-5jvg-8j6f-vpmc

Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-phcg-h58r-gmcq. This link is maintained to preserve external references.

Original Description

PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but

due to the change that was implemented in commit

“7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the

problem of the config partition not being measured correctly.

Also, the “vault” key is sealed/unsealed with SHA1 PCRs instead of

SHA256. 

This issue was somewhat mitigated due to all of the PCR extend functions

updating both the values of SHA256 and SHA1 for a given PCR ID.

However, due to the change that was implemented in commit

“7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, this is no longer the case for PCR14, as

the code in “measurefs.go” explicitly updates only the SHA256 instance of PCR14, which

means that even if PCR14 were to be added to the list of PCRs sealing/unsealing the “vault”

key, changes to the config partition would still not be measured.

An attacker could modify the config partition without triggering the measured boot, this could

result in the attacker gaining full control over the device with full access to the contents of the

encrypted “vault”

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://nvd.nist.gov/vuln/detail/CVE-2023-43630, https://asrg.io/security-advisories/config-partition-not-measured-from-2-fronts, https://asrg.io/security-advisories/cve-2023-43630

Severity

8.8

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
8.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
0.0.0-20230126065759-d9383a7ee4e1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading