LowAdvisoryCISA — cybersecurity advisories· 21 Apr 2026

Siemens TPM 2.0

Severity: Low · Kind: Advisory

Plain-English summary on the way

We've ingested this item but haven't summarised it yet. Read the upstream advisory using the link below in the meantime — the AI summary will appear here once the next run completes.

From the source

View CSAF Summary The products listed below contain a vulnerability that could allow an attacker to perform an out-of-bound read, potentially leading to information disclosure or denial of service of the TPM. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens TPM 2.0 are affected: SIMATIC CN 4100 vers:all/* (CVE-2025-2884) SIMATIC Field PG M5 vers:all/* (CVE-2025-2884) SIMATIC Field PG M6 vers:all/* (CVE-2025-2884) SIMATIC IPC BX-32A vers:intdot/<29.01.09 (CVE-2025-2884) SIMATIC IPC BX-39A vers:intdot/<29.01.09 (CVE-2025-2884) SIMATIC IPC BX-56A vers:intdot/<32.01.09 (CVE-2025-2884) SIMATIC IPC BX-59A vers:intdot/<32.01.09 (CVE-2025-2884) SIMATIC IPC MD-57A vers:intdot/<30.01.10 (CVE-2025-2884) SIMATIC IPC PX-32A vers:intdot/<29.01.09 (CVE-2025-2884) SIMATIC IPC PX-39A vers:intdot/<29.01.09 (CVE-2025-2884) SIMATIC IPC PX-39A PRO vers:intdot/<29.01.09 (CVE-2025-2884) SIMATIC IPC RW-528A vers:intdot/<34.01.02 (CVE-2025-2884) SIMATIC IPC RW-548A vers:intdot/<34.01.02 (CVE-2025-2884) SIMATIC IPC227E vers:all/* (CVE-2025-2884) SIMATIC IPC277E vers:all/* (CVE-2025-2884) SIMATIC IPC427E vers:intdot/<21.01.20 (CVE-2025-2884) SIMATIC IPC477E vers:intdot/<21.01.20 (CVE-2025-2884) SIMATIC IPC477E PRO vers:intdot/<21.01.20 (CVE-2025-2884) SIMATIC IPC627E vers:all/* (

Was this useful?

00000Sign in to react

Plain-English summaries are AI-generated and reviewed for tone, not technical accuracy. For incident response, always rely on the original source linked above.