Trustedcomputinggroup Trusted Platform Module
By the Year
In 2023 there have been 2 vulnerabilities in Trustedcomputinggroup Trusted Platform Module with an average score of 6.7 out of ten. Trusted Platform Module did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2023 as compared to last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 2 | 6.65 |
2022 | 0 | 0.00 |
2021 | 0 | 0.00 |
2020 | 1 | 6.00 |
2019 | 0 | 0.00 |
2018 | 1 | 7.10 |
It may take a day or so for new Trusted Platform Module vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Trustedcomputinggroup Trusted Platform Module Security Vulnerabilities
An out-of-bounds write vulnerability exists in TPM2.0's Module Library
CVE-2023-1017
7.8 - High
- February 28, 2023
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
Memory Corruption
An out-of-bounds read vulnerability exists in TPM2.0's Module Library
CVE-2023-1018
5.5 - Medium
- February 28, 2023
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
Out-of-bounds Read
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down
CVE-2020-26933
6 - Medium
- November 18, 2020
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.
Improper Initialization
An issue was discovered
CVE-2018-6622
7.1 - High
- August 17, 2018
An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It allows local users to overwrite static PCRs of TPM and neutralize the security features of it, such as seal/unseal and remote attestation.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Trustedcomputinggroup Trusted Platform Module or by Trustedcomputinggroup? Click the Watch button to subscribe.
