DSA-2025-232: Security Update for Dell PowerEdge Server for a Trusted Platform Module (TPM) 2.0 Firmware Vulnerability
Samenvatting: Dell PowerEdge Server remediation and guidance is available for Nuvoton NPCT7xx Trusted Platform Module (TPM) 2.0 firmware versions that could be exploited by malicious users to compromise the affected system. ...
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Impact
Medium
Meer details
The consequence of a successful exploit is denial of service of the TPM. Dell recommends that customers review their security posture, including restriction of accounts with administrative privileges from sending commands to the TPM. Customers should consider this review as part of their decision-making process when determining whether to apply the patch. TPM firmware 7.2.5.0 includes mitigation for CVE‑2025‑2884 and systems already updated to it are not affected. However, 7.2.5.0 is not FIPS 140-3 certified, and TPM security policy prevents downgrading once it is installed. TPM firmware version 7.2.4.1 is the official, validated, FIPS 140‑3 and Common Criteria certified release that contains the mitigation for CVE‑2025‑2884. Contact Dell Customer Support for more information.
Gegevens
|
Third-party Component |
CVEs |
More Information |
|
Nuvoton Trusted Platform Module (TPM) 2.0 Firmware |
CVE-2025-2884 |
Getroffen producten en herstel
- The Affected Products and Remediation table above may be updated as more information becomes available.
- Per Nuvoton’s recommendation in their Security Notice, a full power cycle (hard reset) will restore functionality to NPCT7xx in the event of successful exploitation. To perform a hard reset, see KB article 000175626.
Revisiegeschiedenis
|
Revision |
Date |
Description |
|
1.0 |
2025-06-12 |
Initial Release |
|
2.0 |
2025-06-13 |
Updated for enhanced clarity with no changes to content |
|
3.0 |
2026-04-09 |
|
Verwante informatie
Juridische verklaring van afstand
Getroffen producten
Dell EMC XC Core XC450, Dell EMC XC Core XC650, Dell EMC XC Core XC6520, Dell EMC XC Core XC750, Dell EMC XC Core XC750xa, Dell XC Core XC660, Dell XC Core XC660xs, Dell XC Core XC760, Dell XC Core XC760xa, Dell XC Core XC7625, PowerEdge C6520
, PowerEdge C6525, PowerEdge C6615, PowerEdge C6620, PowerEdge HS5610, PowerEdge HS5620, PowerEdge M7725, PowerEdge MX750c, PowerEdge MX760c, PowerEdge R250, PowerEdge R260, PowerEdge R350, PowerEdge R360, PowerEdge R450, PowerEdge R470, PowerEdge R550, PowerEdge R570, PowerEdge R650, PowerEdge R650xs, PowerEdge R6515, PowerEdge R6525, PowerEdge R660, PowerEdge R660xs, PowerEdge R6615, PowerEdge R6625, PowerEdge R670, PowerEdge R6715, PowerEdge R6725, PowerEdge R750, PowerEdge R750XA, PowerEdge R750xs, PowerEdge R7515, PowerEdge R7525, PowerEdge R760, PowerEdge R760XA, PowerEdge R760xd2, PowerEdge R760xs, PowerEdge R7615, PowerEdge R7625, PowerEdge R770, PowerEdge R7715, PowerEdge R7725, PowerEdge R860, PowerEdge R960, PowerEdge T150, PowerEdge T160, PowerEdge T350, PowerEdge T360, PowerEdge T560, PowerEdge XE7740, PowerEdge XE7745, PowerEdge XE8545, PowerEdge XE8640, PowerEdge XE9640, PowerEdge XE9680, PowerEdge XE9680L, PowerEdge XE9685L, PowerEdge XR11, PowerEdge XR12, PowerEdge XR4510c, PowerEdge XR4520c, PowerEdge XR5610, PowerEdge XR7620, PowerEdge XR8610t, PowerEdge XR8620t, Dell EMC XC Core XC7525
...
Artikeleigenschappen
Artikelnummer: 000331010
Artikeltype: Dell Security Advisory
Laatst aangepast: 09 apr. 2026
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.