CVE-2017-15361
MEDIUMInfineon RSA library <1.02.013 - RCE
Title source: llmDescription
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.
Exploits (6)
nomisec
WORKING POC
by Elbarbons · poc
https://github.com/Elbarbons/ROCA-attack-on-vulnerability-CVE-2017-15361
References (22)
... and 2 more
Scores
CVSS v3
5.9
EPSS
0.7344
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (5)
infineon/rsa_library
< 1.02.013
infineon/trusted_platform_firmware
4.31
infineon/trusted_platform_firmware
4.32
infineon/trusted_platform_firmware
6.40
infineon/trusted_platform_firmware
133.32
Published
Oct 16, 2017
Tracked Since
Feb 18, 2026