CVE-2019-16863
14.11.2019, 03:15
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.Enginsight
Vendor | Product | Version |
---|---|---|
st | st33tphf2espi_firmware | 71.0 |
st | st33tphf2espi_firmware | 71.4 |
st | st33tphf2espi_firmware | 71.12 |
st | st33tphf2espi_firmware | 73.0 |
st | st33tphf2espi_firmware | 73.4 |
st | st33tphf2espi_firmware | 73.8 |
st | st33tphf2ei2c_firmware | 73.5 |
st | st33tphf2ei2c_firmware | 73.9 |
st | st33tphf20spi_firmware | 74.0 |
st | st33tphf20spi_firmware | 74.4 |
st | st33tphf20spi_firmware | 74.8 |
st | st33tphf20spi_firmware | 74.16 |
st | st33tphf20i2c_firmware | 74.5 |
st | st33tphf20i2c_firmware | 74.9 |
𝑥
= Vulnerable software versions
References