漏洞信息详情
Infineon Trusted Platform Module Infineon RSA库安全漏洞
漏洞简介
Infineon Trusted Platform Module(TPM)是德国英飞凌(Infineon)科技公司的一款数据加密芯片。Infineon RSA library是其中的一个加密库。
Infineon TPM中的Infineon RSA库1.02.013版本中存在安全漏洞,该漏洞没有正确的处理RSA密钥的生成。攻击者可利用该漏洞破坏加密保护机制。以下版本受到影响:使用0000000000000422 - 4.34之前版本、000000000000062b - 6.43之前版本和0000000000008521 - 133.33之前版本固件的Infineon Trusted Platform Module。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://www.infineon.com/cms/en/product/promopages/tpm-update/?redirId=59160
参考网址
来源:MISC
链接:https://www.infineon.com/cms/en/product/promopages/tpm-update/?redirId=59160
来源:BID
链接:https://www.securityfocus.com/bid/101484
来源:MISC
链接:https://keychest.net/roca
来源:MISC
链接:https://blog.cr.yp.to/20171105-infineon.html
来源:CONFIRM
链接:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00104.html
来源:MISC
链接:https://github.com/iadgov/Detect-CVE-2017-15361-TPM
来源:CERT-VN
链接:https://www.kb.cert.org/vuls/id/307015
来源:MISC
链接:https://github.com/crocs-muni/roca
来源:CONFIRM
链接:https://cert-portal.siemens.com/productcert/pdf/ssa-470231.pdf
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20171024-0001/
来源:CONFIRM
链接:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03789en_us
来源:CONFIRM
链接:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00148.html
来源:MISC
链接:https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update
来源:CONFIRM
链接:http://support.lenovo.com/us/en/product_security/LEN-15552
来源:MISC
链接:https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170012
来源:MISC
链接:https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-estonian-ids/
来源:CONFIRM
链接:https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03801en_us
来源:CONFIRM
链接:https://www.yubico.com/support/security-advisories/ysa-2017-01/
来源:MISC
链接:https://ics-cert.us-cert.gov/advisories/ICSA-18-058-01
来源:MISC
链接:https://monitor.certipath.com/rsatest
来源:MISC
链接:https://crocs.fi.muni.cz/public/papers/rsa_ccs17
来源:MISC
链接:https://dan.enigmabridge.com/roca-vulnerability-impact-on-gemalto-idprime-net-smart-cards/
受影响实体
- Infineon Rsa_library:1.02.013<!--2000-1-1-->
- Infineon Trusted_platform_firmware:133.32<!--2000-1-1-->
- Infineon Trusted_platform_firmware:6.40<!--2000-1-1-->
- Infineon Trusted_platform_firmware:4.32<!--2000-1-1-->
- Infineon Trusted_platform_firmware:4.31<!--2000-1-1-->
补丁
- Infineon Trusted Platform Module Infineon RSA库安全漏洞的修复措施<!--2017-10-19-->
还没有评论,来说两句吧...