STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://tpm.fail | third party advisory |
https://support.f5.com/csp/article/K32412503?utm_source=f5support&%3Butm_medium=RSS | |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03972en_us | third party advisory |
https://support.lenovo.com/us/en/product_security/LEN-29406 | third party advisory |
https://www.st.com/content/st_com/en/campaigns/tpm-update.html | vendor advisory |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190024 | third party advisory |