CVE-2024-29040 - CVE House
Back to Database
Status published Medium CVE-2024-29040

Fapi Verify Quote: Does not detect if quote was not generated by TPM

Vulnerability Description

This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This issue has been patched in version 4.1.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-29040

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

tpm2-software

View all reports →

Affected Software

tpm2-tss
Vulnerable Versions:
< 4.1.0

Timeline

Official Publish: June 28th, 2024
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Weaknesses (CWE)