TROYANOSYVIRUS
Back to CVEs

CVE-2025-62863

CRITICAL
9.8

Description

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published12/16/2025
Last Modified1/13/2026
Sourcenvd
Honeypot Sightings0

Affected Products

amperecomputing:ampereone_a128-34xamperecomputing:ampereone_a128-34x_firmwareamperecomputing:ampereone_a144-24xamperecomputing:ampereone_a144-24x_firmwareamperecomputing:ampereone_a144-26mamperecomputing:ampereone_a144-26m_firmwareamperecomputing:ampereone_a144-27xamperecomputing:ampereone_a144-27x_firmwareamperecomputing:ampereone_a144-33mamperecomputing:ampereone_a144-33m_firmwareamperecomputing:ampereone_a160-28mamperecomputing:ampereone_a160-28m_firmwareamperecomputing:ampereone_a160-28xamperecomputing:ampereone_a160-28x_firmwareamperecomputing:ampereone_a192-26mamperecomputing:ampereone_a192-26m_firmwareamperecomputing:ampereone_a192-26xamperecomputing:ampereone_a192-26x_firmwareamperecomputing:ampereone_a192-32mamperecomputing:ampereone_a192-32m_firmwareamperecomputing:ampereone_a192-32xamperecomputing:ampereone_a192-32x_firmwareamperecomputing:ampereone_a96-36mamperecomputing:ampereone_a96-36m_firmwareamperecomputing:ampereone_a96-36xamperecomputing:ampereone_a96-36x_firmware

Weaknesses (CWE)

CWE-787

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.