Database/Firmware, BMC & network fabric

Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorable
Impact
RSA keys generated inside affected Infineon TPMs are factorable from the public key alone - no access to the machine required. Every key the TPM ever produced is retroactively compromised: attestation identity keys, sealed storage keys, machine certificates, and any SSH or code-signing key an operator generated in the TPM believing it was hardware-protected. For a fleet, that means the attestation evidence you have been collecting is forgeable by anyone who saw a public key.
Who can reach it
No access to the hardware at all. The attacker needs only a public key that the TPM generated - which by definition has been published to whatever service consumed it.
What to do
Two-part and expensive. First a TPM firmware update from the platform OEM, usually shipped inside a BIOS package, so it is a per-node flash plus reboot. Then - and this is the part that gets skipped - every key generated by the vulnerable TPM must be regenerated and re-enrolled, and the old ones revoked. Sealed data must be unsealed before the update or it becomes unrecoverable. Inventory which nodes carry Infineon TPMs before planning; on old hardware the OEM may never have shipped the fix, in which case move the trust anchor off the TPM.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.