Out-of-bounds read in Trusted Computing Group TPM2.0 reference implementation

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-2884?

CVE-2025-2884 is a vulnerability classified as Out-of-bounds Read, affecting TPM2.0 (affected versions: < 1.83). This vulnerability is rated Medium, with a CVSS score of 6.6. Current sources do not report this vulnerability as exploited.

Overview

Original source data

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0.

Affected products and scope

  • Trusted Computing Group TPM2.0 reference implementation: the normalized record marks versions from 0 through less than 1.83 as affected.
  • TCG specification errata: the TCG advisory maps the issue to TPM 2.0 Library Specification v1.83 with Errata Version 2.0 or higher, v1.59 with Errata Version 1.7 or higher, and v1.38 with Errata Version 1.15 or higher. These are specification errata milestones, not a universal package release for every TPM firmware implementation.
  • Intel PTT and SPS: Intel identifies some affected firmware, but its advisory does not state a common firmware version boundary.
  • Infineon OPTIGA TPM: CERT/CC records SLB 9672 and SLB 9673 as affected before FW xx.24, SLB 9670 TPM2.0 before FW 7.86, SLM/SLI 9670 before FW 13.16, and SLB 9665 before FW 5.66; firmware updates are stated to be available.
  • Siemens: the advisory lists SIMATIC Field PG M6 before V26.01.14; SIMATIC IPC427E, IPC477E, IPC477E PRO, and SIPLUS IPC427E before V21.01.20; related IPC BX/PX lines before V29.01.09; IPC BX-56A and BX-59A before V32.01.09; IPC RW-528A and RW-548A before V34.01.02; and IPC MD-57A before V30.01.10. It also lists SIMATIC CN 4100 with hardware versions below FS 05, along with several Field PG, IPC, and ITP1000 lines with no available or planned fix. The status of other TPM products must be confirmed against their own vendor advisories.

Technical details

The CryptHmacSign helper processes command data passed through the ExecuteCommand() entry point. The reference implementation does not adequately validate consistency between the signature scheme and the signature key's algorithm, allowing data to be handled as though incompatible parameters had a valid layout. A specially crafted command can trigger an out-of-bounds read from TPM memory; the TCG advisory states that the read may extend up to 65535 bytes past the end of the buffer. User-mode applications can send malicious commands to TPM firmware based on the affected reference implementation. The amount of disclosure and the availability effect depend on the vendor's buffer layout and implementation; the available evidence does not establish additional implementation details beyond the flaw in CryptHmacSign.

Exploitability

The available evidence describes exploitation through local access to the TPM interface rather than an independent network attack path. An attacker needs authenticated or low-privilege access to the system and must send a specially crafted command or packet to the TPM. The supplied assessment marks attack complexity as low and user interaction as required. The record marks public_exploit as false and does not mark the issue as known exploited; this does not prove that exploitation has never occurred in any environment.

Technical impact

The flaw can cause an out-of-bounds read while processing an HMAC signing command, potentially exposing data in TPM memory. TCG and CERT/CC describe possible information disclosure or denial of service of the TPM, but the concrete severity depends on the vendor implementation and buffer size. The supplied assessment treats confidentiality and availability impact as high and does not establish an integrity impact. The available evidence does not establish arbitrary code execution or data modification, and it does not show that every TPM device is affected.

Business impact

  • Data disclosure: The out-of-bounds read may expose data held in TPM memory, with the extent depending on the specific implementation.
  • Service disruption: The TPM may be made unavailable, affecting systems that depend on TPM functions.
  • Supply-chain exposure: A flaw in the reference implementation may appear in TPM firmware from multiple manufacturers, but exposure is not uniform across products.
  • Remediation cost: Some devices have firmware updates, while the Siemens advisory also lists product lines with no planned fix or no available fix, which may require isolation, replacement, or formal risk acceptance.

Remediation

  1. Prioritize vendor updates: install the TPM firmware or system update provided by the OEM or silicon vendor for the exact model. A fix for one product or branch does not establish that other branches are fixed.
  2. Apply TCG guidance: review and implement the applicable errata for specification v1.83, v1.59, or v1.38 at the errata milestones identified in the TCG advisory. This guidance does not replace confirmation of the exact firmware used by each vendor.
  3. Use published product boundaries: for Infineon products, apply the appropriate firmware update for models with firmware before xx.24, 7.86, 13.16, or 5.66 as listed in the advisory. For Siemens products with a published fix, update to V26.01.14, V21.01.20, V29.01.09, V32.01.09, V34.01.02, or V30.01.10 according to the model.
  4. Handle devices without a fix: obtain the OEM's latest status, assess replacement or removal from environments requiring TPM services, and apply the vendor's system-protection recommendations. Protecting network access is defense-in-depth and does not demonstrate that local TPM access is blocked.
  5. Verify after updating: recheck the model, firmware, TPM state, and dependent functions after deployment, and retain version evidence and vendor confirmation for each product branch.

Detection

  1. Inventory systems containing TPMs, firmware TPMs, and software TPM implementations, then identify the vendor, model, and corresponding firmware branch.
  2. Compare each model with the manufacturer's advisory to determine whether the firmware is based on the TCG reference implementation or uses the CryptHmacSign helper. Do not assume that every system with a TPM is affected.
  3. Check firmware and hardware against the affected or fixed boundaries published by the relevant vendor. Where no public version boundary exists, request confirmation directly from the vendor.
  4. As a precautionary monitoring measure, review TPM or firmware errors, unusual command failures, and TPM unavailability around suspicious local activity. These are general operational signals, not a vulnerability-specific IOC.
  5. The absence of observed logs or errors does not demonstrate safety; the available evidence does not provide a CVE-specific log signature or IOC.
Sources (23)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan