logo

ROCA Crypto Flaw could have big Impact on Internet of Things

ID: 1b8ec7e3-1fa6-52ae-bca1-a84be32e0db9

STIX ID: report--1b8ec7e3-1fa6-52ae-bca1-a84be32e0db9

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2017-10-18

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

A firmware flaw in Infineon Trusted Platform Module (TPM) chipsets' RSA key-generation library weakens generated RSA keys such that an attacker with access to the public key may recover the corresponding private key (practical for keys <2048 bits). The issue spans many vendors and device types, vendors have released firmware updates and Microsoft provided workarounds, but patching at scale is difficult and the vulnerability may persist across IoT and embedded supply chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.