PT-2026-40388 · Amd · Secure Processor

Published

2026-05-12

·

Updated

2026-05-13

·

CVE-2025-61972

CVSS v4.0

8.5

High

VectorAV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions AMD Secure Processor (affected versions not specified)
Description Missing lock bit protection for NBIO registers allows a local attacker with administrative privileges to gain arbitrary System Management Network (SMN) access. This could lead to arbitrary code execution in the AMD Secure Processor (ASP) and compromise the confidentiality and integrity of SEV-SNP guests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61972

Affected Products

Secure Processor