Skip to finding
important · Boot chain

HPE mapped TPM attestation-forgery and RSA secret-recovery flaws into its server line.

Affects

HPE Alletra, Apollo, Edgeline, MicroServer, ProLiant Gen10, Gen10 Plus and Gen11, and Synergy systems using affected Intel CSME or SPS firmware.

The paths require privileged local access to the TPM command interface: object-slot reuse can expose key-certification credentials, while RSA-OAEP timing leaks information about managed ciphertexts.

Detail and 5 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026