Impact
The vulnerability allows an attacker to bypass the freshness check in the AMD SEV‑SNP attestation path of Cocos AI’s intra‑handshake attested TLS. When the expected reportData is nil, empty, or omitted, the verifier accepts unrelated or stale evidence, effectively accepting an attestation that is not bound to the current connection. This can enable an attacker to convince the relying party that a different or outdated trust context is valid, leading to unauthorized trust or privilege escalation against the system. The weakness stems from improper validation of input data as described by CWE‑346.
Affected Systems
The flaw affects the Cocos AI confidential computing system from Ultravioletrs. Versions up to and including 0.8.2 are impacted. A fix was introduced in version 0.9.0, which enforces the required reportData presence and validity.
Risk and Exploitability
With a CVSS score of 9.1 the vulnerability is classified as critical. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation in the wild. The issue is not yet listed in the CISA KEV catalog, but due to the high severity an attacker could attempt exploitation via a remote network connection establishing an attested TLS session. The exploit would require an attacker to supply evidence that bypasses the missing reportData verification, thereby inducing the system to accept a stale or unrelated attestation.
OpenCVE Enrichment