Vulnerability Description
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tpm2-Tools Project | Tpm2.0-Tools | <= 1.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d699PatchThird Party Advisory
- https://github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d699PatchThird Party Advisory
FAQ
What is CVE-2017-7524?
CVE-2017-7524 is a vulnerability with a CVSS score of 7.5 (HIGH). tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC.
How severe is CVE-2017-7524?
CVE-2017-7524 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7524?
Check the references section above for vendor advisories and patch information. Affected products include: Tpm2-Tools Project Tpm2.0-Tools.