Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects Contrast's remote attestation process, potentially allowing an attacker to impersonate trusted components and bypass identity verification. The issue stems from the system accepting attestation reports without verifying the originating hardware.
- Remote impersonation attacks are possible.
- Confirms system trust and identity verification.
- Verify if your systems are affected.
Attack Path
How an attacker could exploit the issue
An attacker could compromise the integrity of secure communications within Contrast by exploiting a flaw in how it verifies attestation reports from trusted execution environments. This would allow an attacker, who can intercept network traffic and control a trusted execution environment, to relay forged attestation reports. This impersonation could trick Contrast into trusting an unauthorized component, potentially leading to a compromise of its identity verification mechanisms.
- Network traffic interception is required.
- Forged attestation reports trigger the vulnerability.
- Defeats identity verification, impersonating components.
Live Threat
Current exploitation, exposure, and threat context
Remote attestation relay attacks could allow an attacker to impersonate a Contrast Coordinator or workload, bypassing identity verification in Contrast's attested TLS. This is possible when an attacker can intercept network traffic and forge attestation reports, provided they have physical control over at least one Trusted Execution Environment (TEE) machine.
- System identity verification.
- Forging attestation reports.
- Bypassing identity checks.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects Contrast's remote attestation mechanism, impacting the integrity of workload identity verification. Identifying and understanding the specific deployment of Contrast components is the critical first step. This may involve platform or infrastructure teams in coordination with security teams responsible for the attested workloads to determine exposure and risk.
- Identify and confirm accountable Contrast owners.
- Verify attestation report reachability and scope.
- Plan remediation or implement compensating controls.