Config Partition Not Protected by Measured Boot
CVE-2023-43634

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
21 September 2023

What is CVE-2023-43634?

A vulnerability exists in Zededa's secure boot process due to an improper configuration in the sealing and unsealing of the 'vault' key. The transition of the configuration measurement from PCR 13 to PCR 14 was not properly reflected in the sealing process, allowing potential attackers to modify the configuration without triggering the measured boot. This flaw enables unauthorized access to the encrypted vault content, jeopardizing device security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

EVE OS 0 < 8.6.0

EVE OS 9.0.0 < 9.5.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ilay Levi
.