PT-2026-6461 · Go · Github.Com/Lf-Edge/Eve

Publicado

2026-02-04

·

Atualizado

2026-02-04

CVSS v3.1

5.2

Média

VetorAV:P/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Impact

PCR14 is not included in the list of PCRs that seal/unseal the vault key. Additionally, the vault key uses SHA1 PCRs instead of SHA256. Thus an attacker with physical access can take out the disk, use a different computer to modify the files in the /config partition, and re-insert the disk and boot without the change being detected by measured boot and remote attestation.

Patches

Fixed in EVE version 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Resources

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-PHCG-H58R-GMCQ

Produtos afetados

Github.Com/Lf-Edge/Eve