ID |
CVE-2025-2884
|
Sažetak |
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0 |
Reference |
|
CVSS |
Base: | 6.6 |
Impact: | 5.2 |
Exploitability: | 1.3 |
|
Pristup |
Vektor | Složenost | Autentikacija |
LOCAL |
LOW |
LOW |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
HIGH |
NONE |
HIGH |
|
CVSS vektor |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H |
Zadnje važnije ažuriranje |
13-06-2025 - 18:15 |
Objavljeno |
10-06-2025 - 18:15 |