Vulnerability affects only Infineon TPMs
According to a
security alert issued by Infineon last week, a vulnerability in the Infineon TPM firmware results in the generation of RSA keys. Only Infineon TPMs based on the TCG specification family 1.2 and 2.0 are affected.
Infineon is one of the many TPM vendors currently used in production, so not all motherboards are affected.
Infineon issued a firmware update last week and has forwarded the update to motherboard vendors which are now working on integrating the Infineon TPM firmware update into all their products.
Long list of affected vendors
TPMs are typically used in business laptops, routers, embedded and IoT devices. Known affected vendors include Acer, ASUS, Fujitsu, HP, Lenovo, LG, Samsung, Toshiba, and other smaller Chromebook vendors.
"The information in this security bulletin should be acted upon as soon as possible," says HP in a
security alert issued today.
"The vulnerability weakens public key resistance against attacks that are used to deduce the corresponding [RSA] private key," said Fujitsu in a
similar alert.
"RSA public keys generated by the Infineon TPM for use by certain software programs should be considered insecure,"
said Lenovo. "Only software that uses RSA keys generated by the TPM is affected by this vulnerability."
The three vendors are working on pushing out firmware updates, and they've published lists of affected products that use Infineon TPMs in their respective advisories.