important · Boot chain
HPE mapped TPM attestation-forgery and RSA secret-recovery flaws into its server line.
Affects
HPE Alletra, Apollo, Edgeline, MicroServer, ProLiant Gen10, Gen10 Plus and Gen11, and Synergy systems using affected Intel CSME or SPS firmware.
The paths require privileged local access to the TPM command interface: object-slot reuse can expose key-certification credentials, while RSA-OAEP timing leaks information about managed ciphertexts.
Detail and 5 sources
HPE published model-level affected ranges and firmware resolutions for both flaws.