« Back to list

Linuxfoundation

Linuxfoundation Edge Virtualization Engine: vulnerabilities and CVEs

Linuxfoundation Edge Virtualization Engine has 5 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months0
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-43632Critical (9.9)0.66%—Sep 21, 2023
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from…
CVE-2023-43631High (8.8)0.17%—Sep 21, 2023
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present, and contains a supported public key, the container will go on to open port 22 and enable sshd…
CVE-2023-43636High (8.8)0.13%—Sep 20, 2023
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured boot” design, the PCR values calculated at different stages of the boot…
CVE-2023-43635High (8.8)0.12%—Sep 20, 2023
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for…
CVE-2023-43630High (8.8)0.11%—Sep 20, 2023
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of…

Other products by Linuxfoundation