Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.
Podatność ta umożliwia napastnikowi odzyskanie prywatnego klucza kryptograficznego na podstawie klucza publicznego. Cyfra 9 pojawia się w oficjalnym identyfikatorze tego błędu bezpieczeństwa w międzynarodowej bazie luk (CVE-2017-15361).
Post summary
The text explains that CVE-2017-15361 enables the recovery of a private cryptographic key from a public key, but offers no PoC, exploit code, patches, or evidence of active exploitation.
"Estonia's use of 2048-bit RSA public key encryption in its ID cards was compromised due to a flaw in the Infineon chip's key generation algorithm, known as the ROCA vulnerability (CVE-2017-15361)."
Post summary
The text discloses that Estonia’s ID cards used 2048‑bit RSA keys generated by Infineon chips, which are vulnerable due to the ROCA flaw (CVE‑2017‑15361).