CNNVD-202511-2594 Information

CNNVD ID

CNNVD-202511-2594

CVE-2025-13609

  • CNNVD Published: 2025-11-24

Description (Chinese)

Keylime是Keylime开源的一个利用 TPM 技术的开源可扩展信任系统。 Keylime存在安全漏洞,该漏洞源于攻击者可注册新代理并覆盖合法代理身份,可能导致绕过安全控制。

Description (English)

Keylime is an open source-enlarged trust system using TPM technology. There is a security loophole in Keylime, which stems from the fact that the attackers can register new agents and cover legal proxy identities, which may lead to the circumvention of security controls.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Keylime

Published

2025-11-24

Last Modified

2026-02-24

References

https://access.redhat.com/security/cve/CVE-2025-13609 https://bugzilla.redhat.com/show_bug.cgi?id=2416761 https://access.redhat.com/security/cve/cve-2025-13609

Share on: