5.9

CVE-2025-61971

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAMD
Produkt AMD EPYC™ 9004 Series Processors
Default Statusaffected
Version GenoaPI_1.0.0.H
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ 7003 Series Processors
Default Statusaffected
Version MilanPI-SP3_1.0.0.J
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ 9005 Series Processors
Default Statusaffected
Version TurinPI_1.0.0.8
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ 8004 Series Processors
Default Statusaffected
Version GenoaPI_1.0.0.H
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ Embedded 7003 Series Processors
Default Statusaffected
Version EmbMilanPI-SP3 1.0.0.D
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Genoa")
Default Statusaffected
Version EmbGenoaPI-SP5 1.0.0.D
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ Embedded 9004 Series Processors (formerly codenamed "Bergamo")
Default Statusaffected
Version EmbGenoaPI-SP5 1.0.0.D
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ Embedded 8004 Series Processors
Default Statusaffected
Version EmbGenoaPI-SP5 1.0.0.D
Status unaffected
HerstellerAMD
Produkt AMD EPYC™ Embedded 9005 Series Processors
Default Statusaffected
Version EmbeddedTurinPI_SP5_1004
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.018
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@amd.com 5.9 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-1233 Security-Sensitive Hardware Controls with Missing Lock Bit Protection

The product uses a register lock bit protection mechanism, but it does not ensure that the lock bit prevents modification of system registers or controls that perform changes to important hardware system configuration.