Impact
The vulnerability allows the Intel TDX attested TLS verifier to accept a TDX QuoteV4 Evidence whose REPORT_DATA field does not match the expected freshness value for the current session because the verifier fails to copy the value into the quote-body policy before validation. A malicious or replayed quote can therefore be accepted, enabling a session‑misbinding attack where application data is released to an unintended attestation context. This flaw effectively bypasses the integrity guarantees normally provided by the attestation process.
Affected Systems
Ultravioletrs Cocos versions 0.8.2 and earlier are affected. The issue was addressed in release 0.9.0, which implements the missing REPORT_DATA check.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity attack affecting confidentiality and integrity. The EPSS score of less than 1% suggests the current probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to supply a malicious or replayed TDX Quote during a TLS handshake, a scenario that could be performed by an adversary with network or privileged access to the verifying application.
OpenCVE Enrichment