Getac Technology Corporation Statement on Trusted Platform Module Firmware Security Update   

 

Notice:

Getac Technology Corporation (“Getac”) continues to work on qualifying and applying the fixes provided by Nuvoton Technology Corporation (“Nuvoton”) to supported Getac systems. Please refer to the table below to identify fixes for your systems.

 

Release Date: 1st Apr, 2022

Last Updated: 26 May, 2023

 

Summary: 

Nuvoton has informed Getac of a potential vulnerability that an attacker with physical access to Nuvoton Trusted Platform Module (“TPM”) NPCT75x (7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography private key via a side-channel attack against ECDSA because of an Observable Timing Discrepancy. (link)

CVEID: CVE-2020-25082

 

Getac Affected Products and Recommendations:

1.      For certain products currently being manufactured or already in the field, Getac will also release solutions for the update. Please check the affected products in the table below. 

2.      The latest version solution is backwards-compatible with the previous version.

Getac Affected Products and Solution

Product Name

CPU Generation

TPM

FW Version

Release Date

Solution Link

A140

10th Gen

7.2.1.0

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

B300

8th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

B360

10th Gen

7.2.1.0

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

F110

8th Gen

7.2.0.1 / 7.2.0.2 

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

F110

11th Gen

7.2.1.0

26 May, 2023

https://support.getac.com/Service/FileReader?fileid=110703&cateid=100183

K120

8th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

K120

11th Gen

7.2.1.0

26 May, 2023

https://support.getac.com/Service/FileReader?fileid=110703&cateid=100183

S410

8th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

S410

11th Gen

7.2.1.0

26 May, 2023

https://support.getac.com/Service/FileReader?fileid=110703&cateid=100183

UX10

8th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

UX10

10th Gen

7.2.1.0

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

V110

8th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

V110

10th Gen

7.2.1.0

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

RX10

7th Gen

7.2.0.1 / 7.2.0.2

30 May, 2022

https://support.getac.com/Service/FileReader/Index?fileid=110401&cateid=100035

* Please note that the schedule above is subject to change due to test status.  

Getac Disclaimer:

All content and other information mentioned in this statement or offered arising from the issue described herein are provided on an “as is ” basis. Getac hereby expressly disclaims any warranties of any kind, express or implied, including without limitation warranties of merchantability, fitness for any particular purpose, non-infringement of intellectual property. All products, information, and figures specified are preliminary based on current expectations and Getac reserves the right to change or update any content thereof at any time without prior notice. Getac assessments have been estimated or simulated using Getac internal analysis or architecture simulation or modeling, and may not represent the actual risk to the users’ local installation and individual environment. Users are recommended to determine the applicability of this statement to their specified environments and take appropriate actions. The use of this statement, and all consequences of such use, is solely at the user’s own responsibility, risk, and expense thereof. In no event shall Getac or any of its affiliates be liable for any and all claims, damages, costs or expenses, including without limitation, loss of profits, loss of data, loss of business expectancy, compensatory, direct, indirect, consequential, punitive, special, or incidental damages or business interruption arising out of or in connection with related to the information contained herein or actions that the user decides to take based thereon. Getac reserves the right to interpret this disclaimer and update this disclaimer whenever necessary.

  • May 26, 2023

Tittle

A file with this name already exists. Would you like to replace the existing one, or skip it, or rename it and keep them both?