Step CA affected by an index out of bounds panic in TPM attestation EKU validation
An attacker can trigger an index out-of-bounds panic in Step CA by sending a crafted attestation key (AK) certificate with an empty Extended Key Usage (EKU) extension during TPM device attestation.