Product
linuxfoundation edge virtualization engine
5 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-43632
CVE-2023-43631
CVE-2023-43636
CVE-2023-43635
CVE-2023-43630
>= 3.0.0 and < 9.5.0
As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited f
< 8.6.0
On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If the file is present,
< 8.6.0
In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault.
< 9.5.0
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Differen
>= 9.0.0 and < 9.5.0
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “763