CVE-2019-16863: St ST33TPHF20I2C Firmware
Medium severity, CVSS 5.9. EPSS: 3.4% chance of exploitation in the next 30 days.
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.
Affected products
- St ST33TPHF20I2C Firmware: version 74.5 only; version 74.9 only
- St ST33TPHF20SPI Firmware: version 74.0 only; version 74.4 only; version 74.8 only; version 74.16 only
- St ST33TPHF2EI2C Firmware: version 73.5 only; version 73.9 only
- St ST33TPHF2ESPI Firmware: version 71.0 only; version 71.4 only; version 71.12 only; version 73.0 only; version 73.4 only; version 73.8 only
Published 2019-11-14. Last modified 2026-06-17.