CVE-2025-13609

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.

Scoring

Severity
HIGH
CVSS base score
8.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
EPSS probability
0.44%
CWE
CWE-694
Published
2025-11-24
Last modified
2026-06-29

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs