← Vulnerability feed

Vulnerability record · CVE-2020-26933 · published 18 November 2020

CVE-2020-26933: Trustedcomputinggroup trusted platform module vulnerability

Trustedcomputinggroup · Trusted Platform Module

Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.

6.0 CVSS 3.1 Medium EPSS 0.30% · top 79.6% CWE-665 · CWE-665
6.0CVSS 3.1 base score, v2 3.6
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-1017Trustedcomputinggroup trusted platform module out-of-bounds write vulnerabilityAn out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptP…EPSS 1.3%7.1CVE-2018-6622Trustedcomputinggroup trusted platform module vulnerabilityAn issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted …EPSS 0.52%5.5CVE-2023-1018Trustedcomputinggroup trusted platform module out-of-bounds read vulnerabilityAn out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDe…EPSS 5.6%7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed6.5CVE-2013-1675Mozilla Firefox and Thunderbird uninitialized memory information disclosureFirefox, Firefox ESR, Thunderbird and Thunderbird ESR fail to properly initialize the nsDOMSVGZoomEvent::mPreviousScale and mNewScale data structures…KEVEPSS 6.7%analysed5.5CVE-2020-27950Apple XNU kernel memory initialization flaw leaks kernel memoryA memory initialization issue in Apple's XNU kernel leaves kernel memory improperly initialized, allowing a malicious application to disclose kernel …KEVEPSS 17%analysed

Source: NIST National Vulnerability Database (record CVE-2020-26933), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.