A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tpm2-tools | May 4, 2022 | Jun 4, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 4, 2021 |
| Centos_linux | — | Upgrade tpm2-toolsUpgrade tpm2-tools-debugsourceUpgrade tpm2-tools-debuginfo | Nov 10, 2021 | Jun 4, 2021 |
| Debian | — | Upgrade tpm2-tools | Jul 30, 2024 | Jun 4, 2021 |
| Oracle_linux | — | Upgrade tpm2-tools | Nov 17, 2021 | May 25, 2021 |
| Redhat_linux | — | Upgrade tpm2-toolsUpgrade tpm2-tools-debuginfoUpgrade tpm2-tools-debugsource | Nov 10, 2021 | Jun 4, 2021 |
| Rocky_linux | — | Upgrade tpm2-tools-debugsourceUpgrade tpm2-toolsUpgrade tpm2-tools-debuginfo | Mar 12, 2024 | Jun 4, 2021 |
| Suse | — | Upgrade tpm2.0-tools | Jun 19, 2021 | Jun 4, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 4, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 4, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub