Ad

CVE-2026-92701

CRITICAL CVSS 3.1: 9,1 EPSS 0.22%
Обновлено 21 сентября 2026
Intel
Параметр Значение
CVSS 9,1 (CRITICAL)
Устранено в версии 0.9.0
Тип уязвимости CWE-354, CWE-346 (Ошибка проверки источника)
Поставщик Intel
Публичный эксплойт Нет

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context.

The issue is fixed in version 0.9.0.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Высокое
Полная утечка данных
Целостность
Высокое
Полная модификация данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v3.1