5.5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.3 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
20.1%
An out-of-bounds read vulnerability exists in TPM2.0βs Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.
CPE | Name | Operator | Version |
---|---|---|---|
trustedcomputinggroup:trusted_platform_module | trustedcomputinggroup trusted platform module | eq | 2.0 |
[
{
"vendor": "Trusted Computing Group",
"product": "TPM2.0",
"versions": [
{
"status": "affected",
"version": "1.59"
}
]
},
{
"vendor": "Trusted Computing Group",
"product": "TPM2.0",
"versions": [
{
"status": "affected",
"version": "1.38"
}
]
},
{
"vendor": "Trusted Computing Group",
"product": "TPM2.0",
"versions": [
{
"status": "affected",
"version": "1.16"
}
]
}
]
5.5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
6.3 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
20.1%