THREAT OPS › Threat News › [NVD] CVE-2025-2884 (MEDIUM 6.6) — TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
[NVD] CVE-2025-2884 (MEDIUM 6.6) — TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
CVE-2025-2884 CVSS: 6.6 MEDIUM Published: 2025-06-10T18:15:30.617
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0
Indicators of compromise
- CVE-2025-2884cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2884