CVE-2025-13375
CRITICAL
9.8
CVSS 3.1
Description
IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (2)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| IBM | Common Cryptographic Architecture | Linux x86,IBM AIX,IBM i,IBM PowerLinux | 7.5.52, 8.4.82 |
| IBM | IBM 4769 Developers Toolkit | — | 7.5.52 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-250 | cna | CWE-250 |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (1)