VYPR
Vendor

Trustedcomputinggroup

Products
8
CVEs
10
Across products
12
Status
Private

Products

8

Recent CVEs

10
  • CVE-2026-6726HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and…

  • CVE-2023-1017HigFeb 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing…

  • CVE-2020-26933HigNov 18, 2020
    risk 0.47cvss 7.2epss 0.00

    Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in…

  • CVE-2018-6622HigAug 17, 2018
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware…

  • CVE-2026-6727MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to…

  • CVE-2025-2884MedJun 10, 2025
    risk 0.36cvss 6.6epss 0.00

    TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

  • CVE-2023-1018MedFeb 28, 2023
    risk 0.36cvss 5.5epss 0.06

    An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.

  • CVE-2020-24332MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.

  • CVE-2024-29040MedJun 28, 2024
    risk 0.21cvss 4.3epss 0.00

    This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this…

  • CVE-2012-0698Nov 26, 2012
    risk 0.04cvss epss 0.11

    tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.