
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-43634 is a security vulnerability affecting EVE OS that involves insufficient protection of credentials and insecure storage of sensitive information. The vulnerability was discovered when a configuration partition measurement was moved from PCR 13 to PCR 14, but PCR 14 was not added to the list of PCRs that seal/unseal the vault key, effectively making the measurement redundant (ASRG Advisory).
The vulnerability stems from a change in commit '56e589749c6ff58ded862d39535d43253b249acf' where the config partition measurement was relocated from PCR 13 to PCR 14, but the corresponding PCR list for key sealing/unsealing was not updated. This oversight renders the PCR 14 measurement ineffective for protecting the vault key. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating local access requirements but high impact potential (ASRG Advisory).
An attacker could potentially modify the config partition without triggering the measured boot, which could result in gaining full control over the device with complete access to the contents of the encrypted vault (ASRG Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."