MEDIUM · 5.9

CVE-2017-15361

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133...

Vulnerability Description

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

CVSS Score

5.9

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
InfineonTrusted Platform Firmware4.31
AcerC720 Chromebook-
AcerChromebase-
AcerChromebase 24-
AcerChromebook 11 C730-
AcerChromebook 11 C730E-
AcerChromebook 11 C735-
AcerChromebook 11 C740-
AcerChromebook 11 C771-
AcerChromebook 11 C771T-
AcerChromebook 11 N7 C731-
AcerChromebook 13 Cb5-311-
AcerChromebook 14 Cb3-431-
AcerChromebook 14 For Work Cp5-471-
AcerChromebook 15 Cb3-531-
AcerChromebook 15 Cb3-532-
AcerChromebook 15 Cb5-571-
AcerChromebook R11-
AcerChromebook R13 Cb5-312T-
AcerChromebox-

References

FAQ

What is CVE-2017-15361?

CVE-2017-15361 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133...

How severe is CVE-2017-15361?

CVE-2017-15361 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-15361?

Check the references section above for vendor advisories and patch information. Affected products include: Infineon Trusted Platform Firmware, Acer C720 Chromebook, Acer Chromebase, Acer Chromebase 24, Acer Chromebook 11 C730.