Database/Firmware, BMC & network fabric

Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorable
Impact
RSA keys generated inside affected Infineon TPMs are factorable from the public key alone - no access to the machine required. Every key the TPM ever produced is retroactively compromised: attestation identity keys, sealed storage keys, machine certificates, and any SSH or code-signing key an operator generated in the TPM believing it was hardware-protected. For a fleet, that means the attestation evidence you have been collecting is forgeable by anyone who saw a public key.
Who can reach it
No access to the hardware at all. The attacker needs only a public key that the TPM generated - which by definition has been published to whatever service consumed it.
What to do
Two-part and expensive. First a TPM firmware update from the platform OEM, usually shipped inside a BIOS package, so it is a per-node flash plus reboot. Then - and this is the part that gets skipped - every key generated by the vulnerable TPM must be regenerated and re-enrolled, and the old ones revoked. Sealed data must be unsealed before the update or it becomes unrecoverable. Inventory which nodes carry Infineon TPMs before planning; on old hardware the OEM may never have shipped the fix, in which case move the trust anchor off the TPM.
References
Related entries
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
- GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryCVE-2025-4382 · GRUB2 with TPM-based LUKS auto-decryption (rescue mode key retention)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.