The vendor explicitly identifies these products as affected by this CVE.
- SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0)
- TIM 1531 IRC (6GK7543-1MX00-0XE0)
- Summary
- An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
- Remediation
- Update to V2.4.8 or later version
