CVE-2025-54510
Received
Received - Intake
Missing Lock Check in AMD EPYC 9005 PSP Enables Local Data Exposure
Publication date: 2026-04-16
Last updated on: 2026-04-16
Assigner: Advanced Micro Devices Inc.
Description
Description
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | epyc_9005_series_cpus | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-414 | A product does not check to see if a lock is present before performing sensitive operations on a resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a missing lock check in the AMD Platform Security Processor found in AMD EPYC 9005 Series CPUs. It allows a privileged attacker with local access to potentially impact the confidentiality of guest systems.
How can this vulnerability impact me? :
The vulnerability can allow a privileged attacker with local access to compromise the confidentiality of guest environments running on affected AMD EPYC 9005 Series CPUs. This means sensitive data within those guest systems could be exposed or accessed improperly.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70