CVE-2019-16863

MEDIUMCVSS 5.9/10EPSS 3.25%

Last modified

CVE-2019-16863 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.. EPSS estimates a 3.25% chance of exploitation in the next 30 days.

Description

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
3.25%

86.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
StSt33tphf2espi Firmware71.0
StSt33tphf2espi Firmware71.4
StSt33tphf2espi Firmware71.12
StSt33tphf2espi Firmware73.0
StSt33tphf2espi Firmware73.4
StSt33tphf2espi Firmware73.8
StSt33tphf2ei2c Firmware73.5
StSt33tphf2ei2c Firmware73.9
StSt33tphf20spi Firmware74.0
StSt33tphf20spi Firmware74.4
StSt33tphf20spi Firmware74.8
StSt33tphf20spi Firmware74.16
StSt33tphf20i2c Firmware74.5
StSt33tphf20i2c Firmware74.9

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-16863?
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
How severe is CVE-2019-16863?
CVE-2019-16863 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 3.25% probability of exploitation in the next 30 days.
How do I fix CVE-2019-16863?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-16863?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST