DSA-2020-021: Dell Client Platform Security Update Advisory for STMicroelectronics' Trusted Platform Module (TPM)

摘要: Dell Client Consumer and Commercial Platforms require a security update to address STMicroelectronics' TPM vulnerabilities.

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

影响

Medium

详情

Updates are available to address the following security vulnerabilities.

  • CVE-2019-16863

 

We encourage customers to review STMicroelectronics’ advisory for further information:

Information on ST's TPM firmware update – ECDSA signature generation

 

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.

Updates are available to address the following security vulnerabilities.

  • CVE-2019-16863

 

We encourage customers to review STMicroelectronics’ advisory for further information:

Information on ST's TPM firmware update – ECDSA signature generation

 

For more information about any of the Common Vulnerabilities and Exposures (CVEs) mentioned here, consult the National Vulnerability Database (NVD) at http://nvd.nist.gov/home.cfm. To search for a particular CVE, use the database’s search utility at http://web.nvd.nist.gov/view/vuln/search.

Dell Technologies 建议所有客户考虑 CVSS 基本分数以及任何相关的时间和环境分数,这可能会影响与特定安全漏洞相关的潜在严重程度。

受影响的产品和补救措施

Affected products:

Dell Client Consumer and Commercial Platforms (see Resolution section below for complete list of affected products).

Remediation:
 

The following TPM firmware version contains a resolution to this vulnerability:

  • Dell TPM 2.0 Firmware versions 74.64 and newer

 

Download and install the latest firmware version from:https://www.dell.com/support/home/en-us?app=drivers

Dell recommends all customers update at the earliest opportunity.

Dell Client Consumer and Commercial Products Affected:

Product

Release Date (MM/DD/YYYY)

Latitude 3400

1/7/2020

Latitude 3500

1/7/2020

Latitude 7400 2-in-1

1/7/2020

Latitude 5401

1/7/2020

Latitude 5501

1/7/2020

Precision 3540

1/7/2020

Latitude 7300

1/7/2020

Latitude 7400

1/7/2020

Latitude 5300

1/7/2020

Latitude 5400

1/7/2020

Latitude 5500

1/7/2020

Precision 3541

1/7/2020

Latitude 5300 2-IN-1

1/7/2020

Latitude 7200 2 in 1

1/7/2020

XPS 7390 2-in-1

1/7/2020

 

Affected products:

Dell Client Consumer and Commercial Platforms (see Resolution section below for complete list of affected products).

Remediation:
 

The following TPM firmware version contains a resolution to this vulnerability:

  • Dell TPM 2.0 Firmware versions 74.64 and newer

 

Download and install the latest firmware version from:https://www.dell.com/support/home/en-us?app=drivers

Dell recommends all customers update at the earliest opportunity.

Dell Client Consumer and Commercial Products Affected:

Product

Release Date (MM/DD/YYYY)

Latitude 3400

1/7/2020

Latitude 3500

1/7/2020

Latitude 7400 2-in-1

1/7/2020

Latitude 5401

1/7/2020

Latitude 5501

1/7/2020

Precision 3540

1/7/2020

Latitude 7300

1/7/2020

Latitude 7400

1/7/2020

Latitude 5300

1/7/2020

Latitude 5400

1/7/2020

Latitude 5500

1/7/2020

Precision 3541

1/7/2020

Latitude 5300 2-IN-1

1/7/2020

Latitude 7200 2 in 1

1/7/2020

XPS 7390 2-in-1

1/7/2020

 

相关信息

受影响的产品

Laptops, Alienware, Latitude, XPS
文章属性
文章编号: 000177719
文章类型: Dell Security Advisory
上次修改时间: 18 8月 2025
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。