← Retour aux CVEs
CVE-2025-62862
MEDIUM4.6
Description
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process running in Non-Secure state or (2) an out-of-bounds write which corrupts Secure or Non-Secure memory, limited to memory mapped to UEFI-MM Secure Partition by the Secure Partition Manager.
Details CVE
Score CVSS v3.14.6
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurNONE
Publie12/16/2025
Derniere modification12/31/2025
Sourcenvd
Observations honeypot0
Produits affectes
amperecomputing:ampereone_a128-34xamperecomputing:ampereone_a128-34x_firmwareamperecomputing:ampereone_a144-24xamperecomputing:ampereone_a144-24x_firmwareamperecomputing:ampereone_a144-26mamperecomputing:ampereone_a144-26m_firmwareamperecomputing:ampereone_a144-27xamperecomputing:ampereone_a144-27x_firmwareamperecomputing:ampereone_a144-33mamperecomputing:ampereone_a144-33m_firmwareamperecomputing:ampereone_a160-28mamperecomputing:ampereone_a160-28m_firmwareamperecomputing:ampereone_a160-28xamperecomputing:ampereone_a160-28x_firmwareamperecomputing:ampereone_a192-26mamperecomputing:ampereone_a192-26m_firmwareamperecomputing:ampereone_a192-26xamperecomputing:ampereone_a192-26x_firmwareamperecomputing:ampereone_a192-32mamperecomputing:ampereone_a192-32m_firmwareamperecomputing:ampereone_a192-32xamperecomputing:ampereone_a192-32x_firmwareamperecomputing:ampereone_a96-36mamperecomputing:ampereone_a96-36m_firmwareamperecomputing:ampereone_a96-36xamperecomputing:ampereone_a96-36x_firmware
Faiblesses (CWE)
CWE-125CWE-787
References
https://amperecomputing.com/products/product-security(cve@mitre.org)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.