PT-2017-3914 · Yubico+3 · Yubikey 4+3

Dusan Klinec

+4

·

Published

2017-10-10

·

Updated

2019-10-03

·

CVE-2017-15361

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Infineon Trusted Platform Module (TPM) firmware versions prior to 0000000000000422 - 4.34 Infineon Trusted Platform Module (TPM) firmware versions prior to 000000000000062b - 6.43 Infineon Trusted Platform Module (TPM) firmware versions prior to 0000000000008521 - 133.33 YubiKey 4 versions prior to 4.3.5
Description The issue is related to the mishandling of RSA key generation in the Infineon RSA library, making it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks. This can be exploited by a remote attacker to reveal the secret part of a key. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 PGP key generation, and the Cached User Data encryption feature in Chrome OS.
Recommendations For Infineon Trusted Platform Module (TPM) firmware versions prior to 0000000000000422 - 4.34, update to a version after 0000000000000422 - 4.34. For Infineon Trusted Platform Module (TPM) firmware versions prior to 000000000000062b - 6.43, update to a version after 000000000000062b - 6.43. For Infineon Trusted Platform Module (TPM) firmware versions prior to 0000000000008521 - 133.33, update to a version after 0000000000008521 - 133.33. For YubiKey 4 versions prior to 4.3.5, update to version 4.3.5 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04743
CVE-2017-15361
MGASA-2017-0395

Affected Products

Bitlocker
Chrome Os
Infineon Trusted Platform Module
Yubikey 4