SA-006: Information leakage via falsified TPM keys
Vulnerability Type: Incorrect Type Conversion or Cast; Sensitive Information in Resource Not Removed Before Reuse
Affected Product(s): NPCT7xx with any Firmware revision prior to 7.2.4.1 and version 7.2.5.0
Fixed Product(s): Firmware Versions: 7.2.4.1 and 7.2.5.1 and above. For details on firmware updates, please contact the system OEM.
Attack Type: Local
Impact: Obtain credentials for falsified TPM keys; Produce fraudulent TPM 2.0 attestations that appear to originate from a legitimate TPM.
Affected Components: The entire TPM.
Severity: High
Detailed Description: An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.
Discoverer(s)/Credits: Liran Perez and Zecharye Galitzky from Intel / TCG VRT0010
CVE Identifier: CVE-2026-6726
粤公网安备 44030502010001号