CVE-2025-2884
בינונית 6.6
תיאור (מקור, אנגלית)
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
מדדים
- CVSS 3.1
-
6.6 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-20/9/2026
- CWE
- CWE-125
קישורים
- https://github.com/stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0…
- https://trustedcomputinggroup.org/about/security/
- https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83…
- https://trustedcomputinggroup.org/wp-content/uploads/VRT0009-Advisory-FINAL.pdf
- https://www.cve.org/CVERecord?id=CVE-2025-49133
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-0120…
- https://www.kb.cert.org/vuls/id/282450
- https://cert-portal.siemens.com/productcert/html/ssa-628843.html