6.6
CVE-2025-2884
- EPSS 0.07%
- Veröffentlicht 10.06.2025 17:29:19
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
HerstellerSiemens
≫
Produkt
SIMATIC CN 4100
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC Field PG M5
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC Field PG M6
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC BX-32A
Default Statusunknown
Version
0
Version <
V29.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC BX-39A
Default Statusunknown
Version
0
Version <
V29.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC BX-56A
Default Statusunknown
Version
0
Version <
V32.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC BX-59A
Default Statusunknown
Version
0
Version <
V32.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC MD-57A
Default Statusunknown
Version
0
Version <
V30.01.10
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC PX-32A
Default Statusunknown
Version
0
Version <
V29.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC PX-39A
Default Statusunknown
Version
0
Version <
V29.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC PX-39A PRO
Default Statusunknown
Version
0
Version <
V29.01.09
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC RW-528A
Default Statusunknown
Version
0
Version <
V34.01.02
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC RW-548A
Default Statusunknown
Version
0
Version <
V34.01.02
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC227E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC277E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC427E
Default Statusunknown
Version
0
Version <
V21.01.20
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC477E
Default Statusunknown
Version
0
Version <
V21.01.20
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC477E PRO
Default Statusunknown
Version
0
Version <
V21.01.20
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC627E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC647E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC677E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC IPC847E
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIMATIC ITP1000
Default Statusunknown
Version
0
Version <
*
Status
affected
HerstellerSiemens
≫
Produkt
SIPLUS IPC427E
Default Statusunknown
Version
0
Version <
V21.01.20
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.218 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.6 | 1.3 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.