CyberRota Analysis
AI-GeneratedThe vulnerability affects trusted execution environments in versions up to and including 0.8.2, where the Intel TDX verification path fails to validate the current-session freshness value during the intra-handshake attested TLS (aTLS) process. This flaw allows a relying party to accept potentially malicious evidence with mismatched or reused reportData, leading to session-misbinding and unauthorized access to application data. Organizations utilizing affected versions should prioritize upgrading to version 0.9.0 to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.