
CVE-2018-6622에 대한 TPM 취약점 점검 도구입니다. 이 도구는 Black Hat Asia 2019 및 Black Hat Europe 2019에서 발표될 예정입니다.
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v1.3 for TPM ," | ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| `-----------------' |," .;'/ | (((( | ,"
+-----------------------+ ;; | | |,"
/_)______________(_/ //' | +---------+
___________________________/___ `,
/ oooooooooooooooo .o. oooo / \,"---------
/ ==ooooooooooooooo==.o. ooo= / ,`\--{-D) ,"
`-----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
Project link: https://github.com/kkamagui/napper-for-tpm
Please contribute your summary report to the Napper project!
"Napper"는 개별 TPM 및 펌웨어 TPM(Intel PTT)을 위한 새로운 취약점 검사 도구입니다. CVE-2018-6622와 알려지지 않은 CVE는 ACPI(고급 구성 및 전원 인터페이스)의 S3 절전 상태 또는 일시 중단과 관련됩니다. 공격자는 S3 절전을 통해 TPM을 무력화할 수 있으며, 플랫폼 구성 레지스터(PCR)를 사용하는 원격 증명 및 봉인/해제 기능이 무력화될 수 있습니다. CVE-2018-6622 및 알려지지 않은 CVE에 대한 자세한 정보를 원하시면 USENIX 논문 A Bad Dream: Subverting Trusted Platform Module While You Are Sleeping과 Black Hat Europe 2019 발표 자료 BitLeaker: Subverting BitLocker with One Vulnerability를 참조하십시오.
Napper와 CVE-2018-6622는 아래 보안 컨퍼런스에서 소개되었습니다.
Intel PTT(Platform Trust Technology)와 관련된 알려지지 않은 CVE는 아래 보안 컨퍼런스에서 소개되었습니다.
아래 데모 비디오를 시청할 수 있습니다.
기여는 언제나 환영합니다. 여러분이 기여하는 Napper의 요약 보고서는 세상을 더 안전하게 만들어 줄 것입니다.
Napper는 GPL v2 라이선스를 따릅니다.
TPM(Trusted Platform Module)은 변조 방지 장치로, 하드웨어 기반 또는 펌웨어 기반 보안 기능을 제공하도록 설계되었습니다. TPM 칩에는 난수 생성기, 비휘발성 저장소, 암호화/복호화 모듈 및 플랫폼 구성 레지스터(PCR)가 포함되어 있어 BitLocker, DM-Crypt, Trusted Boot(tboot), Open Cloud Integrity Technology(Open CIT)와 같은 다양한 보안 애플리케이션에 활용될 수 있습니다.
TPM은 신뢰할 수 있는 플랫폼 구축을 위한 강력한 기반을 제공하기 위해 상용 장치에 널리 배포되었으며, 특히 기업 및 정부 시스템에서 사용되는 장치에 많이 사용됩니다. TPM은 신뢰 플랫폼의 중요한 지점이기 때문에 많은 연구자들이 TPM의 취약점을 찾으려고 노력했으며, 물리적 접근 없이는 이를 깨기 어렵다는 결론을 내렸습니다. 그러나 이제는 더 이상 사실이 아닙니다.
우리가 발견한 취약점은 ACPI(Advanced Configuration and Power Interface)를 통해 TPM을 무력화할 수 있습니다. PC, 노트북 및 서버의 ACPI는 전력 소비를 줄이기 위해 6가지 절전 상태(S0-S5)를 제공합니다. 시스템이 절전 상태에 진입하면 CPU, 장치 및 RAM의 전원이 차단됩니다. 시스템은 보안 장치를 포함한 구성 요소의 전원을 차단하므로, 깨어날 때 이를 다시 초기화해야 하며 이것이 공격 표면이 될 수 있습니다. 우리는 물리적 접근 없이 이 공격 표면에서 취약점을 발견했습니다.
취약점을 완화하기 위해 대책과 함께 TPM의 취약점을 검사하는 새로운 도구 "Napper"도 제시합니다. Napper는 Linux 기반의 부팅 가능한 USB 장치로, 커널 모듈과 취약점 검사 소프트웨어를 포함합니다. Napper로 시스템을 부팅하면 시스템이 잠시 절전 모드에 들어가 취약점을 검사하고 결과를 보고합니다.
Napper는 특수 커널 모듈과 맞춤형 tpm2 도구로 구성됩니다. Napper는 Ubuntu 18.04 기반으로 제작되었으며, Live CD 이미지를 만들기 위해 커스터마이징되었습니다. TPM 취약점을 확인하고 간편한 방법을 원한다면 3.1절로 이동하여 USB 저장 장치에 Napper Live CD 이미지를 사용하십시오. Napper Live CD에는 바이너리 도구뿐만 아니라 Napper의 전체 소스 코드도 포함되어 있습니다. 현재 Ubuntu 18.04를 사용 중이고 처음부터 Napper를 빌드하려면 3.2절로 이동하여 빌드하십시오.
Napper Live CD 이미지는 Napper 프로젝트의 릴리즈 페이지에 있습니다.
Microsoft Windows 운영 체제를 사용하는 경우 Win32 Disk Imager를 사용하여 Napper Live CD 이미지를 USB 저장 장치에 기록하십시오.
Linux 또는 Mac OS X를 사용하는 경우 아래 dd 명령어를 사용하십시오.```
$> sudo dd if=Napper-LiveCD.iso of=/dev/sdX bs=4096 $> sync
### 3.1.3. USB 저장소로 시스템을 재부팅하고 Napper 실행하기
USB 저장소를 연결하고 부트 순서를 변경하여 USB로 부팅하면, 아래 Napper의 부트 메뉴를 볼 수 있으며 첫 번째 옵션을 선택하여 Napper Live CD를 시작할 수 있습니다.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/525cb00d8f948ccc1653bd4fd08c8baf293615ad80ec52082b6c04efe7484f57.png" alt="napper_boot_menu"/> </center>
부트 시퀀스 후에는 데스크탑에 README.txt 파일과 왼쪽 독 바에 Napper 도구 아이콘이 표시됩니다. 시스템을 확인하려면 독 바의 상단 아이콘을 클릭하고 비밀번호로 `napper`를 입력하십시오. Napper 도구의 `ID`와 `비밀번호`는 `napper`로 설정되어 있습니다. Napper가 시스템을 테스트하는 동안 시스템을 절전 모드로 전환했다가 깨웁니다. 따라서 키보드를 입력하여 ACPI S3 절전 상태에서 시스템을 깨워야 합니다.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/50fdb76d396e32fe811b7f9e23849fd4b66fccee5c4325b5f8c4f167938c51b2.png" alt="napper_run"/> </center>
시스템에 TPM 취약점이 있는 경우 Napper는 아래에 시스템이 취약하다는 요약을 보고합니다. 그렇다면 4장으로 이동하여 해당 요약을 [Napper 프로젝트의 이슈 보고](https://github.com/kkamagui/napper-for-tpm/issues) 또는 [웹사이트](https://kkamagui.github.io/)를 통해 저희 프로젝트 Napper에 공유해 주십시오.
<center> <img src="https://assets.kitploit.com/production/public/readmes/28076/37d28f91902c745a21bd3be9c8f373394694127db5037cc4fb522e1e660c0e65.png" alt="napper_summary"/> </center>
## 3.2. Ubuntu 18.04를 사용한 처음부터 Napper 빌드하기 (긴 버전)
### 3.2.1. Ubuntu 18.04 다운로드 및 Napper 소스 코드 클론
Napper는 Ubuntu 18.04를 기반으로 합니다. 따라서 [공식 Ubuntu 웹사이트](https://www.ubuntu.com/download/desktop)에서 다운로드하여 대상 시스템에 설치합니다. 그 후 [Napper 프로젝트 사이트](https://www.github.com/kkamagui/napper-for-tpm)에서 Napper 소스 코드를 클론하고 아래 명령어로 빌드합니다.```
# Clone Napper source code from project site.
$> git clone https://github.com/kkamagui/napper-for-tpm.git
# Build Napper.
$> cd napper-for-tpm
$> ./bootstrap
소스 코드를 빌드한 후 터미널에서 Napper 도구를 실행할 수 있습니다. 터미널에 아래 명령어를 입력하세요. Napper 프론트엔드는 Python 스크립트로 만들어졌습니다.```
$> sudo ./napper.py
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v 1.3 for TPM ,"| ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| -----------------' |," .;'/ | (((( | ," +-----------------------+ ;; | | |," /_)______________(_/ //' | +---------+ ___________________________/___ ,
/ oooooooooooooooo .o. oooo / ,"---------
/ ==ooooooooooooooo==.o. ooo= / ,\--{-D) ," -----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE Made by Seunghun Han, https://kkamagui.github.io Project link: https://github.com/kkamagui/napper-for-tpm
Checking TPM version for testing. [] Checking TPM version... TPM v2.0. [] Your system has TPM v2.0, and vulnerability checking is needed.
Preparing for sleep. [] Checking the TPM vulnerability testing module... Starting. [] Ready to sleep! Please press "Enter" key. [*] After sleep, please press "Enter" key again to wake up.
[*] Waking up now. Please wait for a while. . . . . . . . . . .
... omitted ...
## 3.3. 테스트 예제
아래 결과는 NUC5i5MYHE 모델의 예시입니다. 해당 시스템은 오래된 버전의 BIOS를 사용하며, CVE-2018-6622 취약점이 있습니다.```
[sudo] password for napper:
,----------------, ,---------,
,-----------------------, ," ,"|
," Napper v 1.3 for TPM ,"| ," ," |
+-----------------------+ | ," ," |
| .-----------------Z | | +---------+ |
| | Z | | | | -==----'| |
| | ︶ ︶ z | | | | | |
| | - | | |/----| ==== oo | |
| | | | | ,/| (((( | ,"
| `-----------------' |," .;'/ | (((( | ,"
+-----------------------+ ;; | | |,"
/_)______________(_/ //' | +---------+
___________________________/___ `,
/ oooooooooooooooo .o. oooo / \,"---------
/ ==ooooooooooooooo==.o. ooo= / ,`\--{-D) ,"
`-----------------------------' '----------"
Napper v1.3 for checking a TPM vulnerability, CVE-2018-6622 and unknown CVE
Made by Seunghun Han, https://kkamagui.github.io
Project link: https://github.com/kkamagui/napper-for-tpm
Checking TPM version for testing.
[*] Checking TPM version... TPM v2.0.
[*] Your system has TPM v2.0, and vulnerability checking is needed.
Preparing for sleep.
[*] Checking the TPM vulnerability testing module... Starting.
[*] Ready to sleep! Please press "Enter" key.
[*] After sleep, please press "Enter" key again to wake up.
[*] Waking up now. Please wait for a while. . . . . . . . . . .
[*] Checking the resource manager process... Starting.
[*] Reading PCR values of TPM and checking a vulnerability... Vulnerable.
[*] Show all PCR values:
Bank/Algorithm: TPM_ALG_SHA1(0x0004)
PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Bank/Algorithm: TPM_ALG_SHA256(0x000b)
PCR_00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_01: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_02: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_03: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_04: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_05: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_06: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_07: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_08: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_09: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_10: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_11: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_12: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_13: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_14: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_15: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_16: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
[*] Extending 0xdeadbeef to all static PCRs.
[*] Show all PCR values:
Bank/Algorithm: TPM_ALG_SHA1(0x0004)
PCR_00: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_01: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_02: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_03: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_04: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_05: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_06: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_07: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_08: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_09: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_10: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_11: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_12: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_13: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_14: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_15: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_16: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 7e 96 8a c6 7f 1b 8d 0d 7a 29 58 3b f2 ee 26 d1 1f f1 24 15
Bank/Algorithm: TPM_ALG_SHA256(0x000b)
PCR_00: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_01: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_02: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_03: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_04: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_05: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_06: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_07: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_08: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_09: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_10: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_11: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_12: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_13: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_14: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_15: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_16: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
PCR_17: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_18: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_19: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_20: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_21: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_22: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
PCR_23: 5b 52 9a c4 e7 67 09 01 28 8c c6 ce af 01 46 a6 2e e0 de c7 11 2d 6d 90 ae 69 c2 59 76 d2 ad 41
Summary. Please contribute summary below to the Napper project, https://www.github.com/kkamagui/napper-for-tpm.
[*] Your TPM version is 2.0, and it is vulnerable.
Please download the latest BIOS firmware from the manufacturer's site and update it.
[*] TPM v2.0 information.
Manufacturer: IFX
Vendor strings: SLB9 665
Firmware Version: 00050028 0007B302
Revision: 116
Year: 2014
Day of year: 303
[*] System information.
Baseboard manufacturer: Intel Corporation
Baseboard product name: NUC5i5MYBE
Baseboard version: H47797-205
BIOS vendor: Intel Corporation
BIOS version: MYBDWi5v.86A.0026.2015.0820.1501
BIOS release date: 08/20/2015
System manufacturer:
System product name:
CVE-2018-6622 및 알 수 없는 CVE의 근본 원인은 비정상적인 S3 절전 상태를 적절히 처리하지 못하는 데 있으며, 다음 두 가지 옵션을 통해 취약점을 제거할 수 있습니다.
이 섹션을 여러분을 위해 준비했습니다. 부담 없이 연락해 주십시오.
이 필드는 여러분의 기여로 업데이트할 예정입니다. 현재 보유한 여러 장치를 테스트 중이며 곧 결과를 업데이트하겠습니다.
| 모델 | 상태 | BIOS 공급업체 | BIOS 버전 | BIOS 출시일 (MM/DD/YY) | TPM 2.0 제조업체 | 공급업체 문자열 | TPM 펌웨어 버전 |
|---|
| ASUS Q170M-C | 취약 | American Megatrends Inc. | 4001 | 11/09/2018 | Infineon (IFX) | SLB9665 | 5.51.8.12800 |
| Dell Optiplex 7040 | 취약 | Dell | 1.11.1 | 10/10/2018 | NTC | rls NPCT | 1.3.2.8 |
| Dell Optiplex 7050 | 취약 | Dell | 1.11.0 | 11/01/2018 | NTC | rls NPCT | 1.3.2.8 |
| GIGABYTE H170-D3HP | 취약 | American Megatrends Inc. | F20g | 03/09/2018 | Infineon (IFX) | SLB9665 | 5.61.10.57600 |
| GIGABYTE Q170M-MK | 취약 | American Megatrends Inc. | F23 | 04/12/2018 | Infineon (IFX) | SLB9665 | 5.51.8.12802 |
| HP Spectre x360 | 취약 | American Megatrends | F.24 | 01/07/2019 | Infineon (IFX) | SLB9665 | 5.62.12.13824 |
| Intel NUC5i5MYHE | 취약 | Intel | MYBDWi5v.86A. 0049.2018. 1107.1046 | 11/07/2018 | Infineon (IFX) | SLB9665 | 5.40.7.45826 |
| Lenovo T480 (20L5A00TKR) | 안전 | Lenovo | N24ET44W (1.19 ) | 11/07/2018 | Infineon (IFX) | SLB9670 | 7.63.14.6400 |
| Lenovo T580 | 안전 | Lenovo | N27ET20W (1.06 ) | 01/22/2018 | STMicroelectronics | 73.4.17568.4452 | |
| Microsoft Surface Pro 4 | 안전 | Microsoft Corporation | 108.2439.769 | 12/07/2018 | Infineon (IFX) | SLB9665 | 5.62.12.13826 |