PT-2026-6461 · Go · Github.Com/Lf-Edge/Eve

Published

2026-02-04

·

Updated

2026-02-04

CVSS v3.1

5.2

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Impact

PCR14 is not included in the list of PCRs that seal/unseal the vault key. Additionally, the vault key uses SHA1 PCRs instead of SHA256. Thus an attacker with physical access can take out the disk, use a different computer to modify the files in the /config partition, and re-insert the disk and boot without the change being detected by measured boot and remote attestation.

Patches

Fixed in EVE version 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Resources

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PHCG-H58R-GMCQ

Affected Products

Github.Com/Lf-Edge/Eve