CVE-2023-38201 Details
Description
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| keylime keylime | < 7.5.0 |
CPE
Remediation
| |
| redhat enterprise linux | 9.0 |
CPE
Remediation
| |
| redhat enterprise linux eus | 9.2 |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems | 9.0_s390x |
CPE
Remediation
| |
| redhat enterprise linux for ibm z systems eus | 9.2_s390x |
CPE
Remediation
| |
| redhat enterprise linux for power little endian | 9.0_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux for power little endian eus | 9.2_ppc64le |
CPE
Remediation
| |
| redhat enterprise linux server aus | 9.2 |
CPE
Remediation
| |
| fedoraproject fedora | 38 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Sep 16, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 12, 2024 | Modified Analysis | [email protected] |
| Nov 12, 2023 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Sep 12, 2023 | CVE Modified | [email protected] |
| Sep 5, 2023 | Initial Analysis | [email protected] |