PT-2026-94069 · Opennhp · Opennhp
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenNHP versions prior to 1.0.3
Description
The software selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a
test purpose key, which causes the FallbackVerifier function to execute unconditionally. This allows attackers to bypass attestation verification by including the test purpose key in the evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.Recommendations
Update OpenNHP to version 1.0.3 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opennhp