PT-2018-2676 · Trusted Computing · Trusted Platform Module (Tpm) 2.0
Hyoungchun Kim
+3
·
Published
2018-08-17
·
Updated
2019-10-03
·
CVE-2018-6622
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trusted Platform Module (TPM) 2.0 (affected versions not specified)
Description
The issue affects BIOS firmware producers who interpret a certain portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification in a specific way. It involves an abnormal case not being handled properly by the firmware during S3 sleep, which can clear TPM 2.0 and allow local users to overwrite static PCRs of TPM. This can neutralize the security features of TPM, such as seal/unseal and remote attestation. The vulnerability is related to errors in security settings and can impact the confidentiality, integrity, and availability of protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trusted Platform Module (Tpm) 2.0