← Vulnerability feed

Vulnerability record · CVE-2017-15361 · published 16 October 2017

CVE-2017-15361: Infineon trusted platform firmware vulnerability

Infineon · Trusted Platform Firmware

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

5.9 CVSS 3.0 Medium EPSS 9.8% · top 4.6%
5.9CVSS 3.0 base score, v2 4.3
9.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
44References
17 Jun 2026Last modified by NVD

Description

The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://support.lenovo.com/us/en/product_security/LEN-15552 MitigationThird Party Advisory
http://www.securityfocus.com/bid/101484 Third Party AdvisoryVDB Entry
https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-eston Issue TrackingThird Party Advisory
https://blog.cr.yp.to/20171105-infineon.html
https://cert-portal.siemens.com/productcert/pdf/ssa-470231.pdf
https://crocs.fi.muni.cz/public/papers/rsa_ccs17 Issue TrackingMitigationThird Party Advisory
https://dan.enigmabridge.com/roca-vulnerability-impact-on-gemalto-idprime-net-smart-cards/ Issue TrackingThird Party Advisory
https://github.com/crocs-muni/roca MitigationThird Party Advisory
https://github.com/iadgov/Detect-CVE-2017-15361-TPM MitigationThird Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-058-01
https://keychest.net/roca Issue TrackingMitigationThird Party Advisory
https://monitor.certipath.com/rsatest MitigationThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170012 Issue TrackingPatchThird Party Advisory
https://security.netapp.com/advisory/ntap-20171024-0001/
https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update Issue TrackingMitigationPatchThird Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03789en_us
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03801en_us
https://www.infineon.com/cms/en/product/promopages/tpm-update/?redirId=59160 MitigationVendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00104.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00148.html
https://www.kb.cert.org/vuls/id/307015 Issue TrackingMitigationThird Party AdvisoryUS Government Resource
https://www.yubico.com/support/security-advisories/ysa-2017-01/ MitigationThird Party Advisory
http://support.lenovo.com/us/en/product_security/LEN-15552 MitigationThird Party Advisory
http://www.securityfocus.com/bid/101484 Third Party AdvisoryVDB Entry
https://arstechnica.com/information-technology/2017/10/crypto-failure-cripples-millions-of-high-security-keys-750k-eston Issue TrackingThird Party Advisory
https://blog.cr.yp.to/20171105-infineon.html
https://cert-portal.siemens.com/productcert/pdf/ssa-470231.pdf
https://crocs.fi.muni.cz/public/papers/rsa_ccs17 Issue TrackingMitigationThird Party Advisory
https://dan.enigmabridge.com/roca-vulnerability-impact-on-gemalto-idprime-net-smart-cards/ Issue TrackingThird Party Advisory
https://github.com/crocs-muni/roca MitigationThird Party Advisory
https://github.com/iadgov/Detect-CVE-2017-15361-TPM MitigationThird Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-18-058-01
https://keychest.net/roca Issue TrackingMitigationThird Party Advisory
https://monitor.certipath.com/rsatest MitigationThird Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV170012 Issue TrackingPatchThird Party Advisory
https://security.netapp.com/advisory/ntap-20171024-0001/
https://sites.google.com/a/chromium.org/dev/chromium-os/tpm_firmware_update Issue TrackingMitigationPatchThird Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03789en_us
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03801en_us
https://www.infineon.com/cms/en/product/promopages/tpm-update/?redirId=59160 MitigationVendor Advisory

Track CVE-2017-15361 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2017-15361), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.