Learn about CVE-2020-8918 affecting Google's go-tpm TPM1.2 library versions prior to 0.3.0, allowing eavesdropping attackers to expose key authorization values. Find mitigation steps here.
Google's go-tpm TPM1.2 library versions prior to 0.3.0 are vulnerable to an eavesdropping attack that can expose key authorization values.
Understanding CVE-2020-8918
This CVE involves an improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions before 0.3.0, leading to potential key authorization value exposure.
What is CVE-2020-8918?
The vulnerability in Google's go-tpm TPM1.2 library versions prior to 0.3.0 allows an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey.
The Impact of CVE-2020-8918
Technical Details of CVE-2020-8918
Vulnerability Description
An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead to key authorization value exposure.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates