CVE-2025-13609
BaseFortify
Publication date: 2025-11-24
Last updated on: 2026-03-19
Assigner: Red Hat, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| keylime | keylime | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-694 | The product uses multiple resources that can have the same identifier, in a context in which unique identifiers are required. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in keylime allows an attacker to register a new agent using a different Trusted Platform Module (TPM) device but claim the unique identifier (UUID) of an existing agent. This overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.
How can this vulnerability impact me? :
The vulnerability can lead to an attacker impersonating a legitimate agent by overwriting its identity. This can result in bypassing security controls, potentially allowing unauthorized access, data manipulation, or disruption of services relying on agent authentication.