PT-2026-99455 · Contrast · Contrast
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Contrast versions prior to 1.16.0
Description
The software is susceptible to remote attestation relay attacks. The system accepted any Trusted Execution Environment (TEE) attestation report that verified correctly and contained the expected firmware patch levels and software measurements, without binding the attestation to specific, physically trusted hardware. An attacker capable of intercepting network traffic between the CLI and the Coordinator, or between the Coordinator and an attested component, could relay a report from a TEE machine under their physical control to impersonate a Contrast Coordinator or workload. This process defeats identity verification in the attested TLS (aTLS), a security mechanism used to ensure the identity of communicating parties in a TEE environment.
Recommendations
Update to version 1.16.0 or later.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contrast