CVE-2020-12926

6.4
MEDIUMCVSS v3.1 Base Score
0.21%
LOW RiskEPSS (11th percentile)

The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical access of the device because the power must be repeatedly turned on and off. This potential attack may be used to change confidential information, alter executables signed by key material in the TPM, or create a denial of service of the device.

Published: 11/12/2020
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.4MEDIUM

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

4.4

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

0.21%LOW Exploitation Risk
11th percentile

This vulnerability has a 0.21% probability of being exploited in the next 30 days, ranking higher than 11% of all scored CVEs.

CWE Classification

Advertisement