swtpm project records
2 published records for vendor swtpm project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2020-28407No exploit | In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temposwtpm project · swtpm · CWE-59 | High7.1 | — | 0.3% | Nov 3, 2023 |
22Monitor | CVE-2022-23645No exploit | Out-of-bounds read in swtpmswtpm project · swtpm · CWE-125 | Medium5.5 | — | 0.4% | Feb 18, 2022 |
- CVE-2020-2840728Monitor
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a tempo
HighCVSS 7.1No exploitEPSS 0%swtpm project · swtpmNov 3, 2023
- CVE-2022-2364522Monitor
Out-of-bounds read in swtpm
MediumCVSS 5.5No exploitEPSS 0%swtpm project · swtpmFeb 18, 2022