CVE-2020-26933

Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.38:*:*:*:*:*:*
cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.40:*:*:*:*:*:*
cpe:2.3:a:trustedcomputinggroup:trusted_platform_module:2.0:revision_1.59:*:*:*:*:*:*

History

21 Nov 2024, 05:20

Type Values Removed Values Added
CVSS v2 : 3.6
v3 : 6.0
v2 : 3.6
v3 : 7.2
References () https://trustedcomputinggroup.org/about/security/ - Vendor Advisory () https://trustedcomputinggroup.org/about/security/ - Vendor Advisory
References () https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT004-Advisory-FINAL.pdf - Vendor Advisory () https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT004-Advisory-FINAL.pdf - Vendor Advisory

Information

Published : 2020-11-18 17:15

Updated : 2024-11-21 05:20


NVD link : CVE-2020-26933

Mitre link : CVE-2020-26933

CVE.ORG link : CVE-2020-26933


JSON object : View

Products Affected

trustedcomputinggroup

  • trusted_platform_module
CWE
CWE-665

Improper Initialization