Unauthorized Access Vulnerability in Nuvoton NPCT75x TPM 1.2 Firmware
CVE-2021-32015

6MEDIUM

Key Information:

Vendor

Nuvoton

Vendor
CVE Published:
8 June 2021

What is CVE-2021-32015?

The Nuvoton NPCT75x TPM 1.2 firmware version 7.4.0.0 contains a vulnerability that allows local authenticated users with high privileges to potentially access non-volatile memory without authorization. To mitigate this problem, users are advised to upgrade to firmware version 7.4.0.1; however, it's important to note that this version is not TCG or Common Criteria certified. For further guidance, refer to Nuvoton's security advisory.

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.