Back to overview

CVE-2025-13375

CRITICAL
9.8
CVSS 3.1
Description
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

Metadata

CVE ID
CVE-2025-13375
State
PUBLISHED
Assigner
ibm
Reserved
2025-11-18 19:19 UTC
Published
2026-02-04 20:31 UTC
Last updated
2026-02-06 19:24 UTC
Primary CWE
CWE-250
CWE-250
Vendor / Product
IBM / Common Cryptographic Architecture
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
IBM Common Cryptographic Architecture Linux x86,IBM AIX,IBM i,IBM PowerLinux 7.5.52, 8.4.82
IBM IBM 4769 Developers Toolkit 7.5.52
Weakness (CWE)
CWESourceDescription
CWE-250 cna CWE-250
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview