Impact
A timing side‑channel exists in the RSA OAEP decryption routine of TPM 2.0. By measuring decryption durations, an attacker can recover information sufficient to decrypt ciphertexts that target TPM‑managed RSA keys, such as the Endorsement Key, import blobs, credential blobs, and session salts. The disclosed impact includes exposure of sensitive data and, under certain conditions, the forging of TPM attestations, thereby undermining integrity and authenticity of boot and trust chain data.
Affected Systems
The flaw affects all TPM 2.0 devices and software that implement the RSA OAEP decryption routine. No vendor‑specific version details are disclosed in the CNA data, so any TPM 2.0 implementation may be susceptible unless fixed by firmware or software updates.
Risk and Exploitability
The vulnerability is exploitable only by a privileged local actor who can interact with the TPM command interface. The EPSS score is <1% and the CVSS score of 5.9 indicates moderate severity. It is not listed in the CISA KEV catalog. The severity potential is high because it enables extraction of critical keys and may let an attacker forge attestations. The lack of a publicly disclosed exploit makes the actual exploitation probability uncertain, but the capability demonstrated by the side‑channel is significant for attackers with local access.
OpenCVE Enrichment