PT-2025-50217 · Unknown · Pci Express+1
Published
2025-12-09
·
Updated
2025-12-11
·
CVE-2025-9612
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PCI Express (PCIe) Integrity and Data Encryption (IDE) specification (affected versions not specified)
Description
The PCI Express (PCIe) Integrity and Data Encryption (IDE) specification contains insufficient guidance regarding Transaction Layer Packet (TLP) ordering and tag uniqueness. This deficiency potentially allows encrypted packets to be replayed or reordered without detection. A local or physical attacker on the PCIe bus could exploit this to compromise data integrity protections.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pci Express
Pcie Integrity/Data Encryption