SA-007: A timing side-channel vulnerability in RSA OAEP decryption
Vulnerability Type: Observable Timing Discrepancy
Affected Product(s): NPCT7xx with any Firmware revision prior to 7.2.3.0
Fixed Product(s): Firmware Version: 7.2.3.0 and above. For details on firmware updates, please contact the system OEM.
Attack Type: Local
Impact: Decrypt ciphertexts encrypted to the TPM's RSA Endorsement Key, including credential blobs, import blobs, and session salts.
Affected Components: RSA Endorsement Key
Attack Vector: Side Channel Attack
Severity: Medium
Detailed Description: A timing side-channel vulnerability in RSA OAEP decryption was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to decrypt ciphertexts (import blobs, credential blobs, and session salts) encrypted to the RSA Endorsement Key or falsify TPM 2.0 Attestation Keys.
Discoverer(s)/Credits: Shai Sarfati and Yanai Moyal from Intel / TCG VRT0011
CVE Identifier: CVE-2026-6727
粤公网安备 44030502010001号