Contrast versions before 1.16.0 accept TEE attestation reports that verify successfully and contain expected firmware patch levels and software measurements without binding those reports to particular physically trusted hardware. This permits relay of an otherwise valid attestation report from an attacker-controlled TEE environment to impersonate a Contrast Coordinator or workload in Contrast attested TLS (aTLS).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote attestation relay vulnerability in Contrast before 1.16.0. TEE attestation reports were not cryptographically bound to a particular physically trusted machine, enabling an attacker able to intercept relevant traffic and control or compromise another TEE machine to relay valid attestations and impersonate a Contrast Coordinator or workload, defeating aTLS identity verification.
A remote attestation relay vulnerability in Contrast versions before 1.16.0. An attacker able to intercept relevant network traffic and either forge a report or compromise secrets from a TEE machine under their physical control can relay that report to impersonate a Contrast Coordinator or workload, defeating identity verification in Contrast attested TLS (aTLS).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.