PT-2025-50217 · Unknown · Pci Express+1

Published

2025-12-09

·

Updated

2025-12-11

·

CVE-2025-9612

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PCI Express (PCIe) Integrity and Data Encryption (IDE) specification (affected versions not specified)
Description The PCI Express (PCIe) Integrity and Data Encryption (IDE) specification contains insufficient guidance regarding Transaction Layer Packet (TLP) ordering and tag uniqueness. This deficiency potentially allows encrypted packets to be replayed or reordered without detection. A local or physical attacker on the PCIe bus could exploit this to compromise data integrity protections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2025-9612

Affected Products

Pci Express
Pcie Integrity/Data Encryption