CVE-2019-16863: Medium severity st st33tphf2e vulnerability
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16863?
CVE-2019-16863 is a vulnerability that affects STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12, allowing attackers to extract the ECDSA private key via a side-channel timing attack.
How can attackers exploit CVE-2019-16863?
Attackers can exploit CVE-2019-16863 by performing a side-channel timing attack to extract the ECDSA private key from vulnerable STMicroelectronics ST33TPHF2ESPI TPM devices.
What is the severity of CVE-2019-16863?
CVE-2019-16863 has a severity score of 5.9, which is considered medium.
Which software versions are affected by CVE-2019-16863?
CVE-2019-16863 affects STMicroelectronics ST33TPHF2ESPI Firmware versions 71.0, 71.4, 71.12, 73.0, 73.4, and 73.8.
Where can I find more information about CVE-2019-16863?
You can find more information about CVE-2019-16863 at the following references: http://tpm.fail, https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190024, https://support.f5.com/csp/article/K32412503?utm_source=f5support&utm_medium=RSS