Description

This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This issue has been patched in version 4.1.0.

INFO

Published Date :

2024-06-28T21:02:04.076Z

Last Modified :

2025-11-04T17:19:50.283Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-29040 vulnerability.

Vendors Products
Tpm2 Software
  • Tpm2 Tools
Tpm2 Software Stack Project
  • Tpm2 Software Stack

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact