{"id":"CVE-2021-3565","details":"A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.","modified":"2026-07-08T05:59:45.729002311Z","published":"2021-06-04T12:15:07.557Z","related":["ALSA-2021:4413","SUSE-SU-2021:1998-1","SUSE-SU-2021:1999-1","openSUSE-SU-2021:0934-1","openSUSE-SU-2021:1998-1","openSUSE-SU-2024:11471-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"]},{"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux","cpes":["cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESY6HRYUKR5ZG2K5QAJQC5S6HMKZMFK7/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XK5M7I66PBXSN663TSLAZ3V6TWWFCV7C/"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1964427"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tpm2-software/tpm2-tools","events":[{"introduced":"0"},{"fixed":"4bcbebc852d9849c9f1784880db2accc2eb1a3bf"},{"introduced":"6b6d46de1b30747405cbc0a4ed9759f9bceb9583"},{"fixed":"6976f7a862c4215704d9b824d58d48be4048bd2a"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:tpm2-tools_project:tpm2-tools:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.3.2"},{"introduced":"5.1"},{"fixed":"5.1.1"}]}}],"versions":["4.3.2-rc0","5.1.1-rc0","5.1","4.3.1","4.3.1-rc0","4.2.1","4.3.0","4.3.0-rc1","4.3.0-rc0","4.2.1-rc1","4.2.1-rc0","4.2","4.2-rc1","4.2-RC0","4.1.1-RC1","4.1.1-RC0","4.1","4.1-rc1","4.1-rc0","4.0","4.0-rc2","4.0-rc0","2.0.0","v1.1.0","2.0.0-beta_0","v1.1-beta_1","v1.1-beta_0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3565.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}