PT-2026-109325 · Unknown · Privasys Go
CVE-2026-108267
·
Published
2026-10-09
·
Updated
2026-10-10
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Privasys Go versions prior to 0.5.1-go1.26.5
Description
In the challenge-mode RA-TLS (Remote Attestation TLS) implementation within
crypto/tls, the software fails to bind the ReportData of the attestation quote to the active TLS session, binding it only to the certificate public key and client nonce. This allows an attacker possessing an enclave TLS private key to relay a genuine quote to a different connection. Consequently, a relying party may incorrectly accept a handshake terminated by the attacker as a verified attested enclave connection.Recommendations
Update to version 0.5.1-go1.26.5.
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Privasys Go