The flaw can cause an out-of-bounds read while processing an HMAC signing command, potentially exposing data in TPM memory. TCG and CERT/CC describe possible information disclosure or denial of service of the TPM, but the concrete severity depends on the vendor implementation and buffer size. The supplied assessment treats confidentiality and availability impact as high and does not establish an integrity impact. The available evidence does not establish arbitrary code execution or data modification, and it does not show that every TPM device is affected.