CVE-2025-9612
BaseFortify
Publication date: 2025-12-09
Last updated on: 2026-01-14
Assigner: CERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| pcisig | pci_express_integrity_and_data_encryption | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is related to the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification. It arises because there is insufficient guidance on how Transaction Layer Packet (TLP) ordering and tag uniqueness should be handled. Due to this, encrypted packets can be replayed or reordered without detection, which means an attacker with local or physical access to the PCIe bus could potentially violate data integrity protections.
How can this vulnerability impact me? :
The vulnerability can allow local or physical attackers on the PCIe bus to replay or reorder encrypted packets without detection. This can lead to violations of data integrity protections, potentially causing unauthorized data manipulation or corruption.