The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/ultravioletrs/cocos/agent to version 0.9.0 or higher.
Affected versions of this package are vulnerable to Origin Validation Error during the intra-handshake attestation.. An attacker can impersonate a trusted service endpoint and gain unauthorized access to sensitive data or operations by extracting the ephemeral TLS private key through physical access, transient execution, or side-channel attacks. This is only exploitable if the attacker is able to obtain the ephemeral TLS private key from the target environment.
This vulnerability can be mitigated by keeping TEE firmware and microcode up to date, defining strict attestation policies that validate all available report fields, and enabling mutual attested TLS with CA-signed certificates where possible, though these measures do not fully eliminate the risk.