Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
Vulnerability Description
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13609
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2025:23201
- https://access.redhat.com/errata/RHSA-2025:23210
- https://access.redhat.com/errata/RHSA-2025:23628
- https://access.redhat.com/errata/RHSA-2025:23735
- https://access.redhat.com/errata/RHSA-2025:23852
- https://access.redhat.com/errata/RHSA-2026:0429
- https://access.redhat.com/security/cve/CVE-2025-13609
- https://bugzilla.redhat.com/show_bug.cgi?id=2416761
- https://github.com/keylime/keylime/issues/1820
Affected Vendor
Keylime Project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.