CVE-2025-13375Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-07); latest day: 1
  • 12 total mentions across 5 days

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-02-04: 2Mentions · 2026-02-05: 2Mentions · 2026-02-06: 2Mentions · 2026-02-07: 5Mentions · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-10: 1Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 2Technical Details · 2026-02-07: 502-0402-0502-0602-0702-10
Signal classification3 categories
Disclosure
758.3%
Patch
325.0%
General
216.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-042
Disclosure2
2026-02-052
Disclosure1General1
2026-02-062
Disclosure1Patch1
2026-02-075
Disclosure3General1Patch1
2026-02-101
Patch1
Full discourse12 posts
  • Explain IT Again@xplain_it_again
    Patch

    CVE-2025-13375: Critical IBM Crypto Flaw (CVSS 9.8) Exposes Hardware Security Modules - Time to update those IBM cryptographic coprocessors, folks. #cybersecurity #ibm #vulnerability #cryptography https://explainitagain.wixsite.com/explain-it-again/post/cve-2025-13375-critical-ibm-crypto-flaw-cvss-9-8-exploits-hardware-security-modules

    Post summary

    The post announces IBM CVE‑2025‑13375, a critical flaw that exposes hardware security modules, and urges users to update their cryptographic coprocessors.

    3000075
    1 followersView on X
  • yousukezan@yousukezan
    Patch

    IBMはCommon Cryptographic Architecture(CCA)における深刻な脆弱性CVE-2025-13375を公表した。CVSSは9.8と極めて高く、外部から到達可能な場合、未認証の攻撃者が任意のコマンドを管理者権限で実行できる。 CCAはIBM製HSMとアプリケーションを仲介する中核ソフトであり、侵害されれば暗号鍵の窃取や金融・認証基盤の停止といった最悪の事態を招く。影響を受けるのは4769向けCCA 7の7.5.52、4770向けCCA 8の8.4.82、さらに開発者向けツールキット7.5.52で、AIXやIBM i、PowerLinux、x86 Linuxなど幅広い環境に及ぶ。IBMは既に修正版を提供しており、4769では7.5.53、4770では8.4.84への更新を強く推奨する。HSMを運用する管理者は、最重要インフラ防御の観点から即時対応が求められる。 https://securityonline.info/cve-2025-13375-critical-ibm-crypto-flaw-cvss-9-8-exposes-hsms/

    Post summary

    IBM disclosed CVE‑2025‑13375, a critical RCE flaw in CCA with a CVSS score of 9.8, and released patches (7.5.53/8.4.84) with a strong recommendation for immediate update.

    000201.0K
    11.4K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    IBMの暗号コンポーネントCommon Cryptographic Architecture (CCA)に重大(Critical)な脆弱性。CVE-2025-13375はCVSSスコア9.8で、無認証の攻撃者が特権で任意コードを実行可能。HSMも露出する影響。 https://securityonline.info/cve-2025-13375-critical-ibm-crypto-flaw-cvss-9-8-exposes-hsms/

    Post summary

    IBM's Common Cryptographic Architecture (CCA) is reported to have a critical vulnerability (CVE-2025-13375) with a CVSS score of 9.8, allowing unauthenticated attackers to execute arbitrary privileged code and exposing HSMs.

    00020977
    7.2K followersView on X
  • transilienceai@transilienceai
    Disclosure

    CVE-2025-13375 is a critical vulnerability in IBM's Common Cryptographic Architecture (CCA) software with a CVSS score of 9.8. This allows unauthenticated attackers to execute arbitrary commands with elevated privileges on systems running IBM Hardware Security Modules (HSMs). #CyberSecurity 🚨

    Post summary

    IBM's Common Cryptographic Architecture has a high‑severity vulnerability (CVSS 9.8) that allows unauthenticated attackers to run arbitrary commands on HSMs.

    1000050
    316 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @CrowdCyber_Com CVE-2025-13375 is a critical vulnerability (CVSS 9.8) in IBM's Common Cryptographic Architecture (CCA) software, enabling unauthenticated attackers to execute arbitrary commands with elevated privileges on affected Hardware Security Modules (HSMs). #CyberSecurity #IBM

    Post summary

    IBM’s Common Cryptographic Architecture (CCA) software has a critical CVE-2025-13375 that permits unauthenticated attackers to execute arbitrary commands with elevated privileges on Hardware Security Modules. The post provides technical details but no PoC, exploit, or patch information.

    1000052
    316 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2025-13375: Critical IBM Crypto Flaw (CVSS 9.8) Exposes HSMs https://securityonline.info/cve-2025-13375-critical-ibm-crypto-flaw-cvss-9-8-exposes-hsms/

    Post summary

    The post reports the discovery of a critical IBM Crypto flaw (CVE-2025-13375) exposing HSMs with a CVSS score of 9.8, but it does not provide a PoC, exploit, or patch details.

    1000061
    299 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-13375: CRITICAL] IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.#cve,CVE-2025-13375,#cybersecurity https://cvefind.com/CVE-2025-13375

    Post summary

    IBM Common Cryptographic Architecture 7.5.52/8.4.82 have a critical remote code execution vulnerability allowing unauthenticated command execution with elevated privileges; no PoC, exploit, or patch information is provided.

    00010110
    583 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    IBMのHSM連携基盤「CCA」に深刻な脆弱性(CVE-2025-13375) 早急な更新を推奨 https://rocket-boys.co.jp/security-measures-lab/critical-vulnerability-found-in-ibm-cca-hsm-integration-platform-cve-2025-13375-urgent-update-recommended/

    Post summary

    The post alerts about a critical vulnerability in IBM's CCA HSM integration platform (CVE-2025-13375) and urges an urgent patch, but provides no PoC, exploit code, or detailed technical information.

    0000055
    44 followersView on X
  • Karma-X@Karma_X_Inc
    General

    CVE-2025-13375: Critical IBM Crypto Flaw (CVSS 9.8) Exposes HSMs https://securityonline.info/cve-2025-13375-critical-ibm-crypto-flaw-cvss-9-8-exposes-hsms/

    Post summary

    The post announces a critical IBM Crypto Flaw (CVE-2025-13375) with a CVSS score of 9.8 that could expose Hardware Security Modules, but offers no deeper technical, exploit, or remediation details.

    0000060
    73 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting IBM Common Cryptographic Architecture and 4769 Developers Toolkit (CVE-2025-13375) https://vuldb.com/?id.344419

    Post summary

    The post announces an increased severity for a newly identified vulnerability (CVE-2025-13375) affecting IBM Common Cryptographic Architecture and 4769 Developers Toolkit, but provides no further technical or mitigation details.

    0000096
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13375 IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system. https://www.cve.org/CVERecord?id=CVE-2025-13375

    Post summary

    The text reports CVE-2025-13375 as an unauthenticated command execution vulnerability in IBM CCA 7.5.52/8.4.82, with no evidence of exploitation, PoC, or mitigation steps.

    00000177
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-13375: IBM Common Cryptographic Archite... Unauthenticated RCE with SYSTEM privileges in IBM's crypto stack exposes HSM infrastructure to complete compromise - ze... https://zerodaysignal.com/vulnerability/CVE-2025-13375 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2025-13375, a critical unauthenticated RCE in IBM’s Common Cryptographic Architecture that could grant SYSTEM-level access and fully compromise HSM infrastructure. No exploitation evidence or patches are mentioned.

    0000083
    132 followersView on X

Explore more