CVE-2025-2884 - CERT CVE
ID CVE-2025-2884
Sažetak TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
Reference
CVSS
Base: 6.6
Impact: 5.2
Exploitability:1.3
Pristup
VektorSloženostAutentikacija
LOCAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH NONE HIGH
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
Zadnje važnije ažuriranje 13-06-2025 - 18:15
Objavljeno 10-06-2025 - 18:15