Metrics
Affected Vendors & Products
Fri, 13 Jun 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 and advisory VRT0009 of TCG standard TPM2.0 | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0 |
References |
|
Fri, 13 Jun 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 11 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0 | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 and advisory VRT0009 of TCG standard TPM2.0 |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|
Tue, 10 Jun 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 10 Jun 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0 | |
Title | Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation | |
References |
|

Status: PUBLISHED
Assigner: certcc
Published: 2025-06-10T17:29:19.463Z
Updated: 2025-06-13T18:22:21.856Z
Reserved: 2025-03-27T21:01:41.908Z
Link: CVE-2025-2884

Updated: 2025-06-10T19:02:29.811Z

Status : Awaiting Analysis
Published: 2025-06-10T18:15:30.617
Modified: 2025-06-13T18:15:21.710
Link: CVE-2025-2884

No data.