Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-8918— TPM 1.2 key authorization values are vulnerable to a TPM transport eavesdropper

CVSS 6.3 · Medium EPSS 0.02% · P4
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-8918

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TPM 1.2 key authorization values are vulnerable to a TPM transport eavesdropper
Source: NVD (National Vulnerability Database)
Vulnerability Description
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey. An attacker listening in on the channel can collect both 'encUsageAuth' and 'encMigrationAuth', and then can calculate 'usageAuth ^ encMigrationAuth' as the 'migrationAuth' can be guessed for all keys created with CreateWrapKey. TPM2.0 is not impacted by this. We recommend updating your library to 0.3.0 or later, or, if you cannot update, to call CreateWrapKey with a random 20-byte value for 'migrationAuth'.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
初始化不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Google Go-TPM 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Go-TPM是美国Google公司的一个 Go 开发包,能够在 Linux 平台上直接与 TPM 通信 。TPM 规范中指定的格式能够直接通过缓冲区进行通信 。 go-tpm 0.3.0之前版本中存在安全漏洞,该漏洞源于程序没有正确初始化‘migrationAuth’值。攻击者可利用该漏洞获取CreateWrapKey创建的密钥的auth值。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Google LLCgoogle/go-tpm library stable ~ 0.3.0 -

II. Public POCs for CVE-2020-8918

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-8918

登录查看更多情报信息。

Same Patch Batch · Google LLC · 2020-08-11 · 3 CVEs total

CVE-2020-89115.6 MEDIUMCBC padding oracle in AWS S3 Crypto SDK for GoLang
CVE-2020-89122.5 LOWIn-band key negotiation issue in AWS S3 Crypto SDK for GoLang

IV. Related Vulnerabilities

V. Comments for CVE-2020-8918

No comments yet


Leave a comment