CVE-2025-54510
Received Received - Intake
Missing Lock Check in AMD EPYC 9005 PSP Enables Local Data Exposure

Publication date: 2026-04-16

Last updated on: 2026-04-16

Assigner: Advanced Micro Devices Inc.

Description
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-16
Last Modified
2026-04-16
Generated
2026-05-07
AI Q&A
2026-04-16
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
amd epyc_9005_series_cpus *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-414 A product does not check to see if a lock is present before performing sensitive operations on a resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a missing lock check in the AMD Platform Security Processor found in AMD EPYC 9005 Series CPUs. It allows a privileged attacker with local access to potentially impact the confidentiality of guest systems.


How can this vulnerability impact me? :

The vulnerability can allow a privileged attacker with local access to compromise the confidentiality of guest environments running on affected AMD EPYC 9005 Series CPUs. This means sensitive data within those guest systems could be exposed or accessed improperly.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart