CVE-2023-43630: EVE Doesn't Measure Config Partition From 2 Fronts
PCR14 is not included in the list of PCRs that seal/unseal the vault key. Additionally, the vault key uses SHA1 PCRs instead of SHA256. Thus an attacker with physical access can take out the disk, use a different computer to modify the files in the /config partition, and re-insert the disk and boot without the change being detected by measured boot and remote attestation.
References
- asrg.io/security-advisories/config-partition-not-measured-from-2-fronts
- asrg.io/security-advisories/cve-2023-43630
- github.com/advisories/GHSA-phcg-h58r-gmcq
- github.com/lf-edge/eve
- github.com/lf-edge/eve/commit/d9383a7ee4e1c39f5c8c6d4a63cb2ebd00695e8a
- github.com/lf-edge/eve/security/advisories/GHSA-phcg-h58r-gmcq
- help.zededa.com/hc/en-us/articles/43295940828827-TPM-PCR-Index-Security-Implications
- nvd.nist.gov/vuln/detail/CVE-2023-43630
Code Behaviors & Features
Detect and mitigate CVE-2023-43630 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →