CVE-2019-16863

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
stst33tphf2espi_firmware
71.0
stst33tphf2espi_firmware
71.4
stst33tphf2espi_firmware
71.12
stst33tphf2espi_firmware
73.0
stst33tphf2espi_firmware
73.4
stst33tphf2espi_firmware
73.8
stst33tphf2ei2c_firmware
73.5
stst33tphf2ei2c_firmware
73.9
stst33tphf20spi_firmware
74.0
stst33tphf20spi_firmware
74.4
stst33tphf20spi_firmware
74.8
stst33tphf20spi_firmware
74.16
stst33tphf20i2c_firmware
74.5
stst33tphf20i2c_firmware
74.9
𝑥
= Vulnerable software versions