SA-006: Information leakage via falsified TPM keys

Vulnerability Type: Incorrect Type Conversion or Cast; Sensitive Information in Resource Not Removed Before Reuse

Affected Product(s): NPCT7xx with any Firmware revision prior to 7.2.4.1 and version 7.2.5.0

Fixed Product(s): Firmware Versions: 7.2.4.1 and 7.2.5.1 and above. For details on firmware updates, please contact the system OEM.

Attack Type: Local

Impact: Obtain credentials for falsified TPM keys; Produce fraudulent TPM 2.0 attestations that appear to originate from a legitimate TPM.

Affected Components: The entire TPM.

Severity: High

Detailed Description: An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.

Discoverer(s)/Credits: Liran Perez and Zecharye Galitzky from Intel / TCG VRT0010

CVE Identifier: CVE-2026-6726