CVE-2025-54510

A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Apr 2026, 20:16

Type Values Removed Values Added
Summary (en) Missing lock check in AMD Platform Security Processor in AMD EPYC™ 9005 Series CPUs allows a privileged attacker to potentially impact guest confidentiality via local access. (en) A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.

16 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-16 19:16

Updated : 2026-04-17 15:14


NVD link : CVE-2025-54510

Mitre link : CVE-2025-54510

CVE.ORG link : CVE-2025-54510


JSON object : View

Products Affected

No product.

CWE
CWE-414

Missing Lock Check