logo

CVE-2025-13375: Critical IBM Crypto Flaw (CVSS 9.8) Exposes HSMs

ID: b6027c20-5efb-5ca2-aaef-2b4b5ceb03fc

STIX ID: report--b6027c20-5efb-5ca2-aaef-2b4b5ceb03fc

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-06

Date Updated: 2026-04-23

Author: Ddos

...
...

IBM published a critical security bulletin for its Common Cryptographic Architecture (CVE-2025-13375, CVSS 9.8) that allows unauthenticated arbitrary command execution on 4769 and 4770 cryptographic coprocessors. Affected CCA and toolkit versions and multiple OS platforms (AIX, IBM i, PowerLinux, Linux x86) are identified; IBM has released firmware updates and PTFs and urges immediate patching to prevent key theft and operational disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.