Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amd
Amd epyc 8004 Series Processors Amd epyc 9004 Series Processors Amd epyc 9005 Series Processors Amd epyc Embedded 8004 Series Processors Amd epyc Embedded 9004 Series Processors Amd epyc Embedded 9005 Series Processors |
|
| Vendors & Products |
Amd
Amd epyc 8004 Series Processors Amd epyc 9004 Series Processors Amd epyc 9005 Series Processors Amd epyc Embedded 8004 Series Processors Amd epyc Embedded 9004 Series Processors Amd epyc Embedded 9005 Series Processors |
Wed, 13 May 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | NBIO Register Lock Bit Exposure Grants Local Administrator Arbitrary SMN Access |
Wed, 13 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity. | |
| Weaknesses | CWE-1233 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-05-13T03:03:31.455Z
Reserved: 2025-10-04T18:09:57.018Z
Link: CVE-2025-61972
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:34:58Z
Weaknesses