CVE-2019-16863: St ST33TPHF20I2C Firmware

Medium severity, CVSS 5.9. EPSS: 3.4% chance of exploitation in the next 30 days.

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.

Affected products

  • St ST33TPHF20I2C Firmware: version 74.5 only; version 74.9 only
  • St ST33TPHF20SPI Firmware: version 74.0 only; version 74.4 only; version 74.8 only; version 74.16 only
  • St ST33TPHF2EI2C Firmware: version 73.5 only; version 73.9 only
  • St ST33TPHF2ESPI Firmware: version 71.0 only; version 71.4 only; version 71.12 only; version 73.0 only; version 73.4 only; version 73.8 only

Published 2019-11-14. Last modified 2026-06-17.