CVE-2020-26933: Trustedcomputinggroup Trusted Platform Module

Medium severity, CVSS 6.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.

Affected products

Published 2020-11-18. Last modified 2026-06-17.