Vulnerabilities > CVE-2019-16863 - Information Exposure Through Discrepancy vulnerability in ST products

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
high complexity
st
CWE-203

Summary

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.

Common Weakness Enumeration (CWE)

The Hacker News

idTHN:BAA74F37E5ED293596C20A2281BF1267
last seen2019-11-13
modified2019-11-13
published2019-11-13
reporterThe Hacker News
sourcehttps://thehackernews.com/2019/11/tpm-encryption-keys-hacking.html
titleResearchers Discover TPM-Fail Vulnerabilities Affecting Billions of Devices