英飛凌 Infineon 可信任平台模組 (TPM) 可能產生不安全的 RSA 金鑰

英飛凌 Infineon 可信任平台模組 (TPM) 可能產生不安全的 RSA 金鑰

英飛凌 Infineon 可信任平台模組 (TPM) 可能產生不安全的 RSA 金鑰

Lenovo 資安公告:LEN-15552

可能影響:英飛凌 Infineon 可信任平台模組 (TPM) 使用某些韌體版本產生的 RSA 金鑰可能不安全

嚴重性:因個別情況而異;無到高

影響範圍:全產業

CVE 編號:CVE-2017-15361

概述:

英飛凌 Infineon 生產的可信任平台模組 (TPM),其使用的 RSA 金鑰產生方法中發現了一個安全漏洞,並且該漏洞包含在某些Lenovo產品中。

某些軟體使用由英飛凌TPM生成的RSA金鑰可能不安全,其他廠商的 TPM 並無受到影響。

只有使用由英飛凌 Infineon TPM生成RSA金鑰的軟體才受此安全漏洞的影響。 Lenovo 開發的軟體並無使用該 TPM 產生 RSA 金鑰。想了解更多詳情,請在這裡參閱英飛凌 Infineon 的資安公告。

所謂可信任平台模組 (TPM) 是主機板上的微控制器,用於安全儲存驗證該平台的資料,如密碼、憑證或加密金鑰或是確保系統值得信任的數據。

建議防護應變措施(如何保護您的系統):

解決此問題的步驟順序,取決於您使用的應用程式和/或作業系統。請參考軟體供應商提供的解決說明,以避免在解決此問題時遺失資料。    

  • Microsoft 使用者請按照此處的步驟操作。請先安裝 Microsoft 安全更新,確認您的系統是否受到影響。若系統有受到影響,請按照此公告「可能受影響產品」下的連結安裝 TPM 韌體更新。如果您先安裝 TPM 韌體更新,Microsoft 安全更新中用於偵測系統是否受到影響的工具將出現錯誤結果。Chromebook 使用者請參閱此處的資訊。
  • Lenovo 沒有其他可能使用 TPM 的軟體之相關資訊 (如 WinMagic、Linux 應用程式、其他 Windows 應用程式等)。如果有問題,想知道您應該採取哪些步驟來解決此問題,同時避免遺失資料,您應直接與軟體供應商聯繫。
  • 某些列表中受影響的系統有 2 個 TPM,允許使用者選擇 TPM 1.2 或 TPM 2.0 (兩者只有其一處於啟動狀態)。在英飛凌 Infineon TPM 並非啟動的 TPM 情況下,檢查和更新工具將顯示系統沒有受影響。如果您在未來變更啟動的 TPM,Lenovo 建議您重新執行檢查和更新工具,以確保新設定有更新版本的 TPM 韌體。
  • 即使您目前沒有使用任何依賴 TPM 的軟體,Lenovo 仍建議您執行產品連結中的更新,以防止未來安裝使用 TPM 的軟體時產生削弱的金鑰。

         

可能受影響的產品:

Lenovo 正積極進行修補程式認證,並將英飛凌 Infineon 提供的修補程式應用在支援的系統上。請持續參閱此公告的更新,以取得適用於您系統的修補程式。

Product Impact:

Please click for more info.

Chromebook/Chromebox

Desktop  

Desktop - All in One  - Not affected

IdeaPad - Not affected

Networking Switches  - Not affected

Storage  - Not affected

System x -Lenovo  - Not affected

System x (IBM)  - Not affected

ThinkPad 

ThinkServer  - Not affected

ThinkStation 

ThinkSystem - Not affected

 

Other information and references:

www.infineon.com/tpm-update

https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV170012

WinMagic contains an optional setting to use the TPM for credentials. If this setting is configured, the user will need to perform a password recovery. Please contact WinMagic support for assistance in recovering from a TPM-cleared situation.

 

For a complete list of all Lenovo Product Security Advisories, click here.

Revision History:

Revision

Date

Description

13 11/14/2017 Correction (typo):  There is no ThinkStation P320 Tiny SFF/Tower.  ThinkStation P320 Tiny is affected.  ThinkStation P320 SFF/Tower is not affected.
12 11/13/2017 Correction:  ThinkStation P320 Tiny SFF/Tower are NOT affected.
11 11/10/2017 Clarified ThinkStation P320 Tiny includes all models.
10 11/06/2017 Added ThinkCentre M715q Tiny as not affected.
9 11/01/2017 Added machine types for ThinkPad X1 Carbon/X1 Yoga
8 10/30/2017 Added fix for ThinkPad L560
7 10/24/2017 Added fix links and updated fix targets for ThinkPad.
6 10/23/2017 Added ThinkStation P300/P310 as Not Affected; added link to ThinkCentre TPM1.2 update.
5 10/18/2017 Added fixes for ThinkPad.
4 10/17/2017 Corrected Microsoft links; Added Chromebook/Chromebox; Updated advisory content for clarifications; added CVE
3 10/12/2017 Added ThinkSystem products are not affected.
2 10/11/2017 Added Desktop and ThinkPad status, updated ThinkStation status.

1

10/10/2017

Initial Release

For the most up to date information, please remain current with updates and advisories from Lenovo regarding your equipment and software. The information provided in this advisory is provided on as “as is” basis without any warranty or guarantee of any kind. Lenovo reserves the right to change or update this advisory at any time.

Product Impact:

Chromebook/Chromebox

Refer to Google's advisory for the following Chromebooks:

Lenovo 100S Chromebook

Lenovo Flex 11 Chromebook

Lenovo N20 Chromebook

Lenovo N21 Chromebook

Lenovo N22 (Touch) Chromebook

Lenovo N23 Chromebook

Lenovo N23 Chromebook (Touch)

Lenovo N23 Yoga Chromebook

Lenovo N42 (Touch) Chromebook

ThinkCentre Chromebox

ThinkPad 11e Chromebook

ThinkPad 11e Chromebook 3rd Gen (Yoga/Clamshell)

ThinkPad 13 Chromebook

<Back to Top>

Desktop

Product  Status  Minimum Version Required to Fix  Link to Update Last Updated
IdeaCentre 200 Not affected     10/11/2017
IdeaCentre 300-20IBR Not affected     10/11/2017
IdeaCentre 300-20ISH Not affected     10/11/2017
IdeaCentre 300S-11IBR Not affected     10/11/2017
IdeaCentre 300S-11ISH Not affected     10/11/2017
IdeaCentre 510S-08ISH Not affected     10/11/2017
Ideacentre 700-25ISH Not affected     10/11/2017
Lenovo 63 Not affected     10/11/2017
Lenovo B3300 Not affected     10/11/2017
Lenovo B5900 Not affected     10/11/2017
Lenovo D5005 Not affected     10/11/2017
Lenovo D5055 Not affected     10/11/2017
Lenovo E50-05 Not affected     10/11/2017
Lenovo G5010 Not affected     10/11/2017
Lenovo H3005 Not affected     10/11/2017
Lenovo H30-05 Desktop Not affected     10/11/2017
Lenovo H3050 Not affected     10/11/2017
Lenovo H30-50 Desktop Not affected     10/11/2017
Lenovo H5005 Not affected     10/11/2017
Lenovo H50-05 Desktop Not affected     10/11/2017
Lenovo H50-30g Desktop Not affected     10/11/2017
Lenovo H5050 Not affected     10/11/2017
Lenovo H50-50 Desktop Not affected     10/11/2017
Lenovo M3300 Not affected     10/11/2017
Lenovo M4500 Not affected     10/11/2017
Lenovo M4500 ID Not affected     10/11/2017
Lenovo M4550 ID Not affected     10/11/2017
Lenovo M5900 Not affected     10/11/2017
Lenovo M5900n - China only Not affected     10/11/2017
Lenovo S200 Not affected     10/11/2017
Lenovo S500 Not affected     10/11/2017
QITIAN 4500 Not affected     10/11/2017
QITIAN 4500-C Not affected     10/11/2017
QITIAN B2300 Not affected     10/11/2017
QITIAN B3300 Not affected     10/11/2017
QITIAN B4550 Not affected     10/11/2017
QITIAN B4650 Not affected     10/11/2017
QITIAN B5900 Not affected     10/11/2017
QITIAN M2300 Not affected     10/11/2017
QITIAN M3300 Not affected     10/11/2017
QITIAN M4550 Not affected     10/11/2017
QITIAN M4600 Not affected     10/11/2017
QITIAN M4650 Not affected     10/11/2017
QITIAN M5900 Not affected     10/11/2017
ThinkCentre E73 (SFF) Not affected     10/11/2017
ThinkCentre E73 (TWR) Not affected     10/11/2017
ThinkCentre E73s Not affected     10/11/2017
ThinkCentre E74 Not affected     10/11/2017
ThinkCentre E74s Not affected     10/11/2017
ThinkCentre E79 - China only Not affected     10/11/2017
ThinkCentre E93 (SFF) Not affected     10/11/2017
ThinkCentre E93 (TWR) Not affected     10/11/2017
ThinkCentre M4500k Not affected     10/11/2017
ThinkCentre M4500q Not affected     10/11/2017
ThinkCentre M4500t/s Not affected     10/11/2017
ThinkCentre M4600t/s Not affected     10/11/2017
ThinkCentre M600 Not affected     10/11/2017
ThinkCentre M6500t/s - China only Not affected     10/11/2017
ThinkCentre M6600 Not affected     10/11/2017
ThinkCentre M6600q Not affected     10/11/2017
ThinkCentre M6600t/s Not affected     10/11/2017
ThinkCentre M700 Not affected     10/11/2017
ThinkCentre M710 t/s Affected   TPM 1.2 https://support.lenovo.com/downloads/DS501061
TPM 2.0 target availability 11/30/2017
10/23/2017
ThinkCentre M710q Affected   TPM 1.2 https://support.lenovo.com/downloads/DS501061
TPM 2.0 target availability 11/30/2017
10/23/2017
ThinkCentre M715 t/s Affected   TPM 1.2 https://support.lenovo.com/downloads/DS501061
TPM 2.0 target availability 11/30/2017
10/23/2017
ThinkCentre M715q Tiny Not affected     11/06/2017
ThinkCentre M73 (SFF) Not affected     10/11/2017
ThinkCentre M73 (TWR) Not affected     10/11/2017
ThinkCentre M73 Tiny Not affected     10/11/2017
ThinkCentre M73p Not affected     10/11/2017
ThinkCentre M79 (SFF) Not affected     10/11/2017
ThinkCentre M79 (TWR) Not affected     10/11/2017
ThinkCentre M800 Not affected     10/11/2017
ThinkCentre M83 (SFF) Not affected     10/11/2017
ThinkCentre M83 (Tiny) Not affected     10/11/2017
ThinkCentre M83 (TWR) Not affected     10/11/2017
ThinkCentre M8500t/s - China only Not affected     10/11/2017
ThinkCentre M8600t/s Not affected     10/11/2017
ThinkCentre M900 Not affected     10/11/2017
ThinkCentre M910 t/s/q/x Affected   TPM 1.2 https://support.lenovo.com/downloads/DS501061
TPM 2.0 target availability 11/30/2017
10/23/2017
ThinkCentre M93 Not affected     10/11/2017
ThinkCentre M93P (SFF) Not affected     10/11/2017
ThinkCentre M93P (TWR) Not affected     10/11/2017
ThinkCentre M93P Tiny Not affected     10/11/2017
YANGTIAN AfH110 Not affected     10/11/2017
YANGTIAN AfH81 Not affected     10/11/2017
YANGTIAN AfQ150 Not affected     10/11/2017
YANGTIAN Mc Carrizo-L Not affected     10/11/2017
YANGTIAN Mc Godavari Not affected     10/11/2017
YANGTIAN Mc H110 Not affected     10/11/2017
YANGTIAN Mc H110 PCI Not affected     10/11/2017
YANGTIAN Mc H81 Not affected     10/11/2017
YANGTIAN Me/We H110 Not affected     10/11/2017
YANGTIAN Mf/Wf H110 PCI Not affected     10/11/2017
YANGTIAN Mf/Wf H110 PCI Not affected     10/11/2017
YANGTIAN Mf/Wf H81 PCI Not affected     10/11/2017
YANGTIAN Mf/Wf H81 PCI Not affected     10/11/2017
YANGTIAN Ms/Ws H81 Not affected     10/11/2017
YANGTIAN Ms/Ws H81 Not affected     10/11/2017
YANGTIAN Tc/Wc H110 PCI Not affected     10/11/2017
YANGTIAN Tc/Wc H110 PCI Not affected     10/11/2017
YANGTIAN TC/WCc H81 PCI Not affected     10/11/2017
YANGTIAN TC/WCc H81 PCI Not affected     10/11/2017

<Back to Top>

ThinkPad

Follow the steps below for ThinkPad products:

  1. Identify if your system is affected or not
  2. Download the TPM Firmware update tool
  3. Update the system BIOS to the version level of “Minimum Version Required to Fix” as indicated in the below table.
  4. Follow the instructions in the README to run the TPM Firmware Update tool
Product  Status  Minimum Version Required to Fix  Link to Update Last Updated
ThinkPad 10  Not Affected     10/11/2017
ThinkPad 11e / ThinkPad 11e Yoga (20HS, 20HU) Affected 1.09 https://pcsupport.lenovo.com/downloads/ds120787 10/24/2017
ThinkPad 11e/Yoga 11e  Not Affected     10/11/2017
ThinkPad 11e/Yoga 11e (20G8, 20GA) Affected   Target availability 12/11/2017 10/24/2017
ThinkPad 11e/Yoga 11e (20G9 20GB) Affected 1.19 http://pcsupport.lenovo.com/downloads/ds112170 10/24/2017
ThinkPad 13 (20GJ, 20GK) Affected 1.25 https://pcsupport.lenovo.com/downloads/DS112474 10/24/2017
ThinkPad 25 Affected 1.42 https://pcsupport.lenovo.com/downloads/DS120429 10/11/2017
ThinkPad E450/E450c/E550/E550c  Not Affected     10/11/2017
ThinkPad E455/E555 Not Affected     10/11/2017
ThinkPad E460/E560  Affected   Target availability 12/11/2017 10/24/2017
ThinkPad E465/E565 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad E470/E570 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad E475/E575 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad E570p / ThinkPad S5 Not Affected     10/11/2017
ThinkPad Edge E130 Not Affected     10/11/2017
ThinkPad Edge E135 Not Affected     10/11/2017
ThinkPad Edge E330 Not Affected     10/11/2017
ThinkPad Edge E335 Not Affected     10/11/2017
Thinkpad Edge E430 Not Affected     10/11/2017
ThinkPad Edge E431/E531 Not Affected     10/11/2017
ThinkPad Edge E435 Not Affected     10/11/2017
ThinkPad Edge E440/E540  Not Affected     10/11/2017
ThinkPad Edge E445/E545 Not Affected     10/11/2017
ThinkPad Edge E530 Not Affected     10/11/2017
ThinkPad Edge E535 Not Affected     10/11/2017
ThinkPad Helix (20CG, 20CH) Not Affected     10/11/2017
ThinkPad Helix (3xxx) Not Affected     10/11/2017
ThinkPad L330 Not Affected     10/11/2017
ThinkPad L430/L530 Not Affected     10/11/2017
ThinkPad L440/L540 Not Affected     10/11/2017
ThinkPad L450 Not Affected     10/11/2017
ThinkPad L460 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad L470 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad L560 Affected 1.33 https://pcsupport.lenovo.com//downloads/DS112214 10/30/2017
ThinkPad L570 Not Affected     10/24/2017
ThinkPad P40 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad P50 Affected 1.46 https://pcsupport.lenovo.com/downloads/DS106108 10/11/2017
ThinkPad P50s Affected 1.22 https://pcsupport.lenovo.com/downloads/DS112310 10/11/2017
ThinkPad P51 Affected 1.14 https://pcsupport.lenovo.com/downloads/DS121296 10/11/2017
ThinkPad P51s  (20Jx, 20Kx) Not Affected     10/11/2017
ThinkPad P51s (20Hx) Affected 1.26 https://pcsupport.lenovo.com/downloads/DS120369 10/24/2017
ThinkPad P70 Affected 2.19 https://pcsupport.lenovo.com/downloads/DS106085 10/11/2017
ThinkPad P71 (20Hx) Affected 1.14 https://pcsupport.lenovo.com/downloads/DS121301 10/11/2017
ThinkPad S1 Yoga (Non-vPro) Not Affected     10/11/2017
ThinkPad S1 Yoga (vPro) Not Affected     10/11/2017
ThinkPad S1 Yoga 12 Not Affected     10/11/2017
ThinkPad S3 Yoga 14 Not Affected     10/11/2017
ThinkPad S3-S440 Not Affected     10/11/2017
ThinkPad S430 Not Affected     10/11/2017
ThinkPad S431 Not Affected     10/11/2017
ThinkPad S5 Yoga 15 Not Affected     10/11/2017
ThinkPad S5/E560p Not Affected     10/11/2017
ThinkPad S531 Not Affected     10/11/2017
ThinkPad S540 Not Affected     10/11/2017
ThinkPad T420, T420i Not Affected     10/11/2017
ThinkPad T420s, T420si Not Affected     10/11/2017
ThinkPad T430, T430i Not Affected     10/11/2017
ThinkPad T430s Not Affected     10/11/2017
ThinkPad T430u Not Affected     10/11/2017
ThinkPad T431s Not Affected     10/11/2017
ThinkPad T440/T440s Not Affected     10/11/2017
ThinkPad T440p Not Affected     10/11/2017
ThinkPad T450/T450s  Not Affected     10/11/2017
ThinkPad T460  Affected 1.29 https://pcsupport.lenovo.com/downloads/DS112122 10/24/2017
ThinkPad T460p  Affected 2.2 http://support.lenovo.com/downloads/DS112077 10/24/2017
ThinkPad T460s Affected 1.28 https://pcsupport.lenovo.com/downloads/DS112117 10/11/2017
ThinkPad T470 (20Hx) Affected 1.42 https://pcsupport.lenovo.com/downloads/DS120429 10/11/2017
ThinkPad T470 (20Jx) Not Affected     10/11/2017
ThinkPad T470p Affected 1.17 http://pcsupport.lenovo.com/downloads/DS120707 10/24/2017
ThinkPad T470s (20Hx) Affected 1.19 https://pcsupport.lenovo.com/downloads/DS120418 10/11/2017
ThinkPad T470s (20Jx) Not Affected     10/11/2017
ThinkPad T520, T520i Not Affected     10/11/2017
ThinkPad T530, T530i Not Affected     10/11/2017
ThinkPad T540/T540p Not Affected     10/11/2017
ThinkPad T550 Not Affected     10/11/2017
ThinkPad T560 Affected 1.22 https://pcsupport.lenovo.com/downloads/DS112310 10/11/2017
ThinkPad T570 (20Hx) Affected 1.26 https://pcsupport.lenovo.com/downloads/DS120369 10/24/2017
ThinkPad T570 (20Jx) Not Affected     10/11/2017
ThinkPad Tablet 10 (32-bit) Not Affected     10/11/2017
ThinkPad Tablet 10 (64-bit) Not Affected     10/11/2017
ThinkPad Tablet 2 Not Affected     10/11/2017
ThinkPad Tablet 8 (32-bit) Not Affected     10/11/2017
ThinkPad Tablet 8 (64-bit) Not Affected     10/11/2017
ThinkPad Twist/S230u Not Affected     10/11/2017
ThinkPad W520 Not Affected     10/11/2017
ThinkPad W530 Not Affected     10/11/2017
ThinkPad W540/W541 Not Affected     10/11/2017
ThinkPad W550s Not Affected     10/11/2017
ThinkPad X1 Carbon (20Ax) Not Affected     10/11/2017
ThinkPad X1 Carbon (20Bx) Not Affected     10/11/2017
ThinkPad X1 Carbon (20Hx) Affected 1.24 https://pcsupport.lenovo.com/downloads/DS120390 10/11/2017
ThinkPad X1 Carbon (20Kx) Not Affected     10/11/2017
ThinkPad X1 Carbon (34xx) Not Affected     10/11/2017
ThinkPad X1 Carbon, X1 Yoga (20FB, 20FC, 20FQ, 20FR) Affected 1.31 https://pcsupport.lenovo.com/downloads/DS111756 11/01/2017
ThinkPad X1 Tablet (20Gx) Affected 1.71 https://pcsupport.lenovo.com/downloads/DS112372 10/24/2017
ThinkPad X1 Tablet (20Jx) Affected 1.17 https://pcsupport.lenovo.com/downloads/DS120971 10/24/2017
ThinkPad X1 Yoga  (20Jx) Affected 1.18 https://pcsupport.lenovo.com/downloads/DS121063 10/24/2017
ThinkPad X1; X1 Hybrid Not Affected     10/11/2017
ThinkPad X131e (AMD) Not Affected     10/11/2017
ThinkPad X131e (Intel) Not Affected     10/11/2017
ThinkPad X140e (AMD) Not Affected     10/11/2017
ThinkPad X220, X220i, X220 Tablet Not Affected     10/11/2017
ThinkPad X230 Tablet; X230i Tablet Not Affected     10/11/2017
ThinkPad X230, X230i Not Affected     10/11/2017
ThinkPad X230s/X231s Not Affected     10/11/2017
ThinkPad X240 Not Affected     10/11/2017
ThinkPad X240s Not Affected     10/11/2017
ThinkPad X250  Not Affected     10/11/2017
ThinkPad X260 Affected 1.33 https://pcsupport.lenovo.com/downloads/DS105890 10/24/2017
ThinkPad X270 Affected 1.23 https://pcsupport.lenovo.com/downloads/DS120442 10/24/2017
ThinkPad Yoga 370 /ThinkPad S1 3rd Affected 1.19 http://pcsupport.lenovo.com/downloads/DS120869 10/11/2017
ThinkPad Yoga 11e Not Affected     10/11/2017
ThinkPad Yoga 14 460 S3 Affected   Target availability 12/11/2017 10/24/2017
ThinkPad Yoga 260, S1 Affected 1.61 https://pcsupport.lenovo.com/downloads/DS105460 10/11/2017

<Back to Top>

ThinkStation

Product  Status  Minimum Version Required to Fix  Link to Update Last Updated
ThinkStation C30 (type 1136-1137) Not Affected     10/10/2017
ThinkStation D30 (type 4353-4354) Not Affected     10/10/2017
ThinkStation P300 Not Affected     10/23/2017
ThinkStation P310 Not Affected     10/23/2017
ThinkStation P320 Tiny  Affected  

TPM 1.2 target availability 10/20/2017

TPM 2.0 target availability 11/30/2017

11/13/2017
ThinkStation P320 SFF/Tower Not Affected     11/14/2017
ThinkStation P410 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P500 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P510 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P700 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P710 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P900 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation P910 Affected v4.43 https://support.lenovo.com/downloads/ds500996 10/10/2017
ThinkStation S30 (type 4351-4352) Not Affected     10/10/2017

<Back to Top>


別名 Id:LEN-15552
文件ID:PS500130
原始發布日期:03/02/2018
Last Modified Date:03/02/2018