CVE-2017-15361, known as ROCA, is a critical vulnerability in Infineon RSA library firmware that allows attackers to derive private RSA keys due to flawed key generation. This impacts numerous products from vendors like Dell, HP, Lenovo, and Google, affecting technologies such as BitLocker and YubiKey. Rated as Medium severity (CVSS 5.9), it has a high potential for compromise of confidentiality, though it requires high attack complexity. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion and media coverage, indicating its importance and the potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.31CPE matchmatch criteria | cpe:2.3:o:infineon:trusted_platform_firmware:4.31:*:*:*:*:*:*:* | ||
4.32CPE matchmatch criteria | cpe:2.3:o:infineon:trusted_platform_firmware:4.32:*:*:*:*:*:*:* | ||
6.40CPE matchmatch criteria | cpe:2.3:o:infineon:trusted_platform_firmware:6.40:*:*:*:*:*:*:* | ||
133.32CPE matchmatch criteria | cpe:2.3:o:infineon:trusted_platform_firmware:133.32:*:*:*:*:*:*:* | ||
<= 1.02.013CPE matchmatch criteria | cpe:2.3:a:infineon:rsa_library:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.