Database/Firmware, BMC & network fabric

TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`
CVSS 7.8CVE-2023-1017Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write in CryptParameterDecryption — code execution inside the TPM or a bricked TPM. If the TPM is the root of trust for attestation, a compromised TPM invalidates every measured-boot claim the cloud makes to its tenants
Who can reach it
Local, low privilege
What to do
TPM firmware update from the TPM/platform vendor; TPM firmware updates frequently clear the TPM, which invalidates sealed keys and any disk encryption bound to PCRs — this is why fleets skip it
References
Related entries
- TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident dataCVE-2023-1018 · TPM 2.0 reference implementationMedium
- AMD Secure Processor - TOCTOU race: A time-of-check-to-time-of-use race in the ASP lets an attacker swap a valueCVE-2023-20548 · AMD Secure Processor - TOCTOU raceHigh
- NVIDIA DGX BMC (IPMI handler): Buffer overflow in the IPMI handler of the NVIDIA DGX BMCCVE-2023-25505 · NVIDIA DGX BMC (IPMI handler)High
- AMD Secure Processor - XGMI Trusted Agent (TOCTOU): A TOCTOU race in the ASP's XGMI Trusted Agent lets an attackerCVE-2023-31324 · AMD Secure Processor - XGMI Trusted Agent (TOCTOU)High
- Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method): The firmware reads a runtime UEFI variableCVE-2023-34195 · Insyde InsydeH2O (SystemFirmwareManagementRuntimeDxe, GetImage method)High
- AMI MegaRAC SPx 12 / SPx 13 (BMC): Untrusted pointer dereference in the BMC that a low-privileged actor can turnCVE-2023-34332 · AMI MegaRAC SPx 12 / SPx 13 (BMC)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.