Database/Firmware, BMC & network fabric

STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private key
Impact
Discrete TPM leaks ECDSA nonce data through timing, allowing private key recovery from observed signatures. The discrete-chip half of TPM-FAIL - which matters because the usual answer to the fTPM flaw is 'use a real TPM', and this shows the real TPM had the same class of problem.
Who can reach it
Local attacker able to request signatures from the TPM, with accurate timing measurement.
What to do
TPM firmware update from ST, distributed through the platform OEM's BIOS package - per-node flash plus reboot, and vendor availability was patchy. Rotate any long-lived key the TPM produced. Where no update exists, treat that TPM's keys as software-grade rather than hardware-protected.
References
Related entries
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
- GRUB2 TPM auto-unlock: forced rescue mode leaves the LUKS volume decrypted with the key still in memoryCVE-2025-4382 · GRUB2 with TPM-based LUKS auto-decryption (rescue mode key retention)Medium
- AMD Secure Processor firmware - MMIO routing lock (Zen 5): A missing lock check in ASP firmware on some Zen 5 partsCVE-2025-54510 · AMD Secure Processor firmware - MMIO routing lock (Zen 5)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.