Database/Firmware, BMC & network fabric

tpm2-tss (FAPI quote verification): The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATED
Impact
The JSON quote info returned by Fapi_Quote accepts an arbitrary TPM2_GENERATED magic value, so a malicious device can hand back a quote that the library accepts but that the TPM never produced. That is attestation forgery: a compromised node convinces the verifier it booted a measured, clean image. For any operator selling verified bare metal or confidential GPU compute, this breaks the assertion the whole product rests on - and it breaks it silently, since a forged quote validates.
Who can reach it
A malicious or compromised endpoint being attested. The attacker is the machine claiming to be healthy, not a third party on the wire.
What to do
Update tpm2-tss to 4.1.0 or later wherever your attestation verifier runs and restart the service - package-level, no firmware, no reboot. Then re-run attestation across the fleet, because any quote validated by the old library proves nothing. Worth auditing whether your verifier does its own magic-value check rather than trusting the library.
References
Related entries
- Lenovo XClarity Controller (XCC) - audit log: When an account username is exactly 16 characters, XCC writes the IPMICVE-2024-8059 · Lenovo XClarity Controller (XCC) - audit logMedium
- Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local userCVE-2025-31938 · Intel Xeon 6 Scalable processors with Intel TDX (subsystem access control)Medium
- Arista DANZ Monitoring Fabric: debug API exposes config database contents including user password hashesCVE-2025-54548 · Arista DANZ Monitoring Fabric (debug API exposing the config database)Medium
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveCVE-2018-12038 · Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commandsMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2025-20044 · Intel TDX moduleMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.