The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.
Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
User Interaction None
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.73437.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Acer
Subscribe
|
C720 Chromebook
Subscribe
Chromebase
Subscribe
Chromebase 24
Subscribe
Chromebook 11 C730
Subscribe
Chromebook 11 C730e
Subscribe
Chromebook 11 C735
Subscribe
Chromebook 11 C740
Subscribe
Chromebook 11 C771
Subscribe
Chromebook 11 C771t
Subscribe
Chromebook 11 N7 C731
Subscribe
Chromebook 13 Cb5-311
Subscribe
Chromebook 14 Cb3-431
Subscribe
Chromebook 14 For Work Cp5-471
Subscribe
Chromebook 15 Cb3-531
Subscribe
Chromebook 15 Cb3-532
Subscribe
Chromebook 15 Cb5-571
Subscribe
Chromebook R11
Subscribe
Chromebook R13 Cb5-312t
Subscribe
Chromebox
Subscribe
Chromebox Cxi2
Subscribe
|
|
Aopen
Subscribe
|
|
|
Asi
Subscribe
|
Chromebook
Subscribe
|
|
Asus
Subscribe
|
Chromebit Cs10
Subscribe
Chromebook C200
Subscribe
Chromebook C201pa
Subscribe
Chromebook C202sa
Subscribe
Chromebook C300
Subscribe
Chromebook C300sa
Subscribe
Chromebook C301sa
Subscribe
Chromebook Flip C100pa
Subscribe
Chromebook Flip C302
Subscribe
Chromebox Cn60
Subscribe
Chromebox Cn62
Subscribe
|
|
Bobicus
Subscribe
|
Chromebook 11
Subscribe
|
|
Ctl
Subscribe
|
|
|
Dell
Subscribe
|
|
|
Edugear
Subscribe
|
|
|
Edxis
Subscribe
|
|
|
Epik
Subscribe
|
Chromebook Elb1101
Subscribe
|
|
Google
Subscribe
|
Pixel
Subscribe
|
|
Haier
Subscribe
|
|
|
Hexa
Subscribe
|
Chromebook Pi
Subscribe
|
|
Hisense
Subscribe
|
Chromebook 11
Subscribe
|
|
Hp
Subscribe
|
Chromebook
Subscribe
Chromebook 11-vxxx
Subscribe
Chromebook 11 1100-1199
Subscribe
Chromebook 11 2000-2099
Subscribe
Chromebook 11 2100-2199
Subscribe
Chromebook 11 2200-2299
Subscribe
Chromebook 11 G1
Subscribe
Chromebook 11 G2
Subscribe
Chromebook 11 G3
Subscribe
Chromebook 11 G4\/g4 Ee
Subscribe
Chromebook 11 G5
Subscribe
Chromebook 11 G5 Ee
Subscribe
Chromebook 13 G1
Subscribe
Chromebook 14
Subscribe
Chromebook 14 Ak000-099
Subscribe
Chromebook 14 G3
Subscribe
Chromebook 14 G4
Subscribe
Chromebook 14 X000-x999
Subscribe
Chromebox Cb1-\(000-099\)
Subscribe
Chromebox G1
Subscribe
|
|
Infineon
Subscribe
|
|
|
Lenovo
Subscribe
|
100s Chromebook
Subscribe
N20 Chromebook
Subscribe
N21 Chromebook
Subscribe
N22 Chromebook
Subscribe
N23 Chromebook
Subscribe
N23 Flex 11 Chromebook
Subscribe
N23 Yoga 11 Chromebook
Subscribe
N42 Chromebook
Subscribe
Thinkcentre Chromebox
Subscribe
Thinkpad 11e Chromebook
Subscribe
Thinkpad 13 Chromebook
Subscribe
|
|
Lg
Subscribe
|
|
|
Medion
Subscribe
|
|
|
Mercer
Subscribe
|
|
|
Ncomputing
Subscribe
|
Chromebook Cx100
Subscribe
|
|
Nexian
Subscribe
|
Chromebook
Subscribe
|
|
Pcmerge
Subscribe
|
Chromebook Pcm-116t-432b
Subscribe
|
|
Poin2
Subscribe
|
|
|
Positivo
Subscribe
|
Chromebook Ch1190
Subscribe
|
|
Prowise
Subscribe
|
|
|
Rgs
Subscribe
|
Education Chromebook
Subscribe
|
|
Samsung
Subscribe
|
|
|
Sector-five
Subscribe
|
E1 Rugged Chromebook
Subscribe
|
|
Senkatel
Subscribe
|
C1101 Chromebook
Subscribe
|
|
Toshiba
Subscribe
|
|
|
True
Subscribe
|
|
|
Videonet
Subscribe
|
|
|
Viglen
Subscribe
|
|
|
Xolo
Subscribe
|
Chromebook
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
|
No data.
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:57:25.602Z
Reserved: 2017-10-15T00:00:00
Link: CVE-2017-15361
No data.
Status : Deferred
Published: 2017-10-16T17:29:00.243
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-15361
No data.
OpenCVE Enrichment
No data.
Weaknesses