VDB
CVE-2021-3505
CVE-2021-3505
PUBLISHED
CVSS 5.5 MEDIUM
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
EPSS 0.13% · 31.5th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.13%
31.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | enterprise_linux | 8.0 |
| libtpms_project | libtpms | 0 |
| n/a | libtpms | * |
| fedoraproject | fedora | 33 |
Timeline
- Apr 19, 2021 CVE Published
- Apr 20, 2021 EPSS Score
- Jun 28, 2021 EPSS Score
- Aug 30, 2021 EPSS Score
- Oct 31, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 5, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 6, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1950046 url
- https://github.com/stefanberger/libtpms/issues/183 url
- FEDORA-2021-cfdc434610 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3505 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NUCZX4S53TUNTSGTCRDNOQZV2V2RI4RJ url