CVE-2021-32015
Summary
| CVE | CVE-2021-32015 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-08 17:15:00 UTC |
| Updated | 2021-06-21 19:27:00 UTC |
| Description | In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 will mitigate against the vulnerability, but version 7.4.0.1 is not TCG or Common Criteria (CC) certified. Nuvoton recommends that users apply the NPCT75x TPM 1.2 firmware update. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nuvoton | Npct75x | 1.2 | All | All | All |
| Operating System | Nuvoton | Npct75x Firmware | 7.4.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SA-001: Unauthorized Access to Non-Volatile Memory - Nuvoton | MISC | www.nuvoton.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.