A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-tpm2-tools | May 4, 2022 | Jun 4, 2021 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jun 4, 2021 | |
| Centos_linux | — | centos-upgrade-tpm2-toolscentos-upgrade-tpm2-tools-debuginfocentos-upgrade-tpm2-tools-debugsource | Nov 10, 2021 | Jun 4, 2021 |
| Debian | debian-upgrade-tpm2-tools | Jul 30, 2024 | Jun 4, 2021 | |
| Oracle_linux | — | oracle-linux-upgrade-tpm2-tools | Nov 17, 2021 | May 25, 2021 |
| Redhat_linux | redhat-upgrade-tpm2-toolsredhat-upgrade-tpm2-tools-debuginforedhat-upgrade-tpm2-tools-debugsource | Nov 10, 2021 | Jun 4, 2021 | |
| Rocky_linux | rocky-upgrade-tpm2-toolsrocky-upgrade-tpm2-tools-debuginforocky-upgrade-tpm2-tools-debugsource | Mar 12, 2024 | Jun 4, 2021 | |
| Suse | — | suse-upgrade-tpm2-0-tools | Jun 19, 2021 | Jun 4, 2021 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jun 4, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jun 4, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub