SSA-628843 PUBLISHED CVSS 6.599999904632568 MEDIUM

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

Risk Scores

CVSS v3.1
6.599999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H

Affected Products

VendorProductVersions
SiemensSIMATIC IPC PX-39A PRO
SiemensSIMATIC Field PG M5
SiemensSIMATIC IPC BX-39A
SiemensSIMATIC IPC277E
SiemensSIMATIC CN 4100
SiemensSIMATIC IPC BX-32A
SiemensSIMATIC IPC MD-57A
SiemensSIMATIC IPC847E
SiemensSIPLUS IPC427E
SiemensSIMATIC IPC677E
SiemensSIMATIC IPC RW-528A
SiemensSIMATIC IPC477E
SiemensSIMATIC IPC BX-56A
SiemensSIMATIC Field PG M6
SiemensSIMATIC IPC647E
SiemensSIMATIC ITP1000
SiemensSIMATIC IPC RW-548A
SiemensSIMATIC IPC477E PRO
SiemensSIMATIC IPC627E
SiemensSIMATIC IPC PX-39A

…and 4 more

Timeline

References

Open in Interactive Console →