Vulnerability Description
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trustedcomputinggroup | Trusted Platform Module | 2.0 |
Related Weaknesses (CWE)
References
- https://trustedcomputinggroup.org/about/security/Vendor Advisory
- https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT004-Advisory-FINAL.pdVendor Advisory
- https://trustedcomputinggroup.org/about/security/Vendor Advisory
- https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT004-Advisory-FINAL.pdVendor Advisory
FAQ
What is CVE-2020-26933?
CVE-2020-26933 is a vulnerability with a CVSS score of 7.2 (HIGH). Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE...
How severe is CVE-2020-26933?
CVE-2020-26933 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26933?
Check the references section above for vendor advisories and patch information. Affected products include: Trustedcomputinggroup Trusted Platform Module.