CVE-2025-13375: Critical IBM Crypto Flaw (CVSS 9.8) Exposes HSMs
ID: b6027c20-5efb-5ca2-aaef-2b4b5ceb03fc
STIX ID: report--b6027c20-5efb-5ca2-aaef-2b4b5ceb03fc
Feed Name: securityonline.info
Threat Score
IBM published a critical security bulletin for its Common Cryptographic Architecture (CVE-2025-13375, CVSS 9.8) that allows unauthenticated arbitrary command execution on 4769 and 4770 cryptographic coprocessors. Affected CCA and toolkit versions and multiple OS platforms (AIX, IBM i, PowerLinux, Linux x86) are identified; IBM has released firmware updates and PTFs and urges immediate patching to prevent key theft and operational disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
