Skip to content

Config Partition Not Protected by Measured Boot

Moderate
eriknordmark published GHSA-wc42-fcjp-v8vq Feb 4, 2026

Package

gomod github.com/lf-edge/eve/pkg/evetpm (Go)

Affected versions

< 10.1.0 and < 9.4.3-lts

Patched versions

10.1.0 and 9.4.3-lts

Description

Impact

Config partition measurement was moved from PCR 13 to PCR 14 in a commit, but PCR 14 was not added to the list of PCRs that seal/unseal the vault key.

As a result an attacker can remove the disk, use another server to modify the files in the config partition, and then re-insert the disk.

Patches

Fixed in EVE version 9.4.3-lts

Workarounds

No (apart from preventing physical access to the device)

References

https://help.zededa.com/hc/en-us/articles/43295940828827-TPM-PCR-Index-Security-Implications
d9383a7

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Physical
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

CVE ID

CVE-2023-43634

Weaknesses

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. Learn more on MITRE.

Insecure Storage of Sensitive Information

The product stores sensitive information without properly limiting read or write access by unauthorized actors. Learn more on MITRE.