Database/Firmware, BMC & network fabric

Discrete TPM (LPC / SPI bus, unencrypted sessions): A discrete TPM talks to the CPU over LPC or SPI in the clear unless
Impact
A discrete TPM talks to the CPU over LPC or SPI in the clear unless the software explicitly uses parameter-encrypted sessions, which most does not. An attacker who clips a logic analyser onto the bus - or onto the exposed pins of a socketed TPM header - reads the sealed key as it is released. The demonstrated case is recovering a BitLocker/LUKS volume key in minutes with a cheap probe, on a machine whose owner believed the disk was hardware-protected. For an operator, this is the flaw that turns a physically accessible node into a full data disclosure, and it leaves no trace in any log.
Who can reach it
Physical access to the motherboard for the duration of one boot. In practice: a colo cage neighbour, remote-hands staff, a decommissioning or RMA handler, or hardware intercepted in shipping. No credentials, no software exploit, no persistence needed.
What to do
No patch exists - it is a property of the bus, not a bug. Mitigations are architectural: enable TPM parameter encryption / encrypted sessions in the software that unseals (recent Linux and Windows stacks support it, older ones do not), require a PIN or second factor so the TPM value alone is not sufficient to unlock, prefer fTPM where the bus is internal to the package, and use tamper-evident chassis with a documented seal check on every physical touch. Treat any node that left your custody as untrusted until re-provisioned.
References
Related entries
- Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU package: Re-runsNCVD-2021-005-intel-cpus-with-sgx-attacked-ove · Intel CPUs with SGX, attacked over the SVID serial bus between the voltage regulator and the CPU packageUnscored
- DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrink: A different read-disturbanceNCVD-2023-001-ddr4-chips-from-all-three-major · DDR4 chips from all three major DRAM manufacturers; worsens as process nodes shrinkUnscored
- Gigabyte UEFI firmware (OEM update-dropper in firmware): Gigabyte firmware shipped a UEFI module that writes a WindowsNCVD-2023-001-gigabyte-uefi-firmware-oem-updat · Gigabyte UEFI firmware (OEM update-dropper in firmware)Unscored
- Intel processors with Linear Address Masking (LAM): SLAM: Linear Address Masking, a feature intended to let softwareNCVD-2023-001-intel-processors-with-linear-add · Intel processors with Linear Address Masking (LAM)Unscored
- MSI / Intel Boot Guard OEM key leak: The Money Message ransomware dump exposed MSI's firmware image-signing privateNCVD-2023-001-msi-intel-boot-guard-oem-key-lea · MSI / Intel Boot Guard OEM key leakUnscored
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-001-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.