CVE-2020-26933: Trustedcomputinggroup Trusted Platform Module
Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.
Affected products
- Trustedcomputinggroup Trusted Platform Module: version 2.0 only
Published 2020-11-18. Last modified 2026-06-17.