Back to search
CVE-2019-16863
Published: Nov 14, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://tpm.fail
x_refsource_MISC
https://support.lenovo.com/us/en/product_security/LEN-29406
x_refsource_CONFIRM
https://www.st.com/content/st_com/en/campaigns/tpm-update.html
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now