High severity7.5NVD Advisory· Published Jun 27, 2017· Updated May 13, 2026
CVE-2017-7524
CVE-2017-7524
Description
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client to server when generating HMAC.
Affected products
2- cpe:2.3:a:tpm2-tools_project:tpm2.0-tools:*:*:*:*:*:*:*:*Range: <=1.1.0
- TPM 2.0 Tools/tpm2-toolsv5Range: before 1.1.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/01org/tpm2.0-tools/commit/c5d72beaab1cbbbe68271f4bc4b6670d69985157nvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.