PT-2025-51800 · Gigabyte · Gigabyte Motherboards

Mohamed Al-Sharifi

+1

·

Published

2025-12-17

·

Updated

2025-12-24

·

CVE-2025-14302

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GIGABYTE motherboard models (affected versions not specified)
Description A protection mechanism failure exists in certain GIGABYTE motherboard models due to improperly enabled IOMMU. This allows unauthenticated physical attackers with a DMA-capable PCIe device to read and write arbitrary physical memory before the operating system kernel and its security features are loaded. IOMMU (Input/Output Memory Management Unit) is a component of a motherboard that manages memory access for peripheral devices. When not properly enabled, it can lead to direct memory access (DMA) attacks, where an attacker can bypass the operating system and directly access system memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2026-00893
CVE-2025-14302

Affected Products

Gigabyte Motherboards