LiveActive security incident?Get immediate response
CVE Record

CVE-2025-54510: A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attac...

A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, potentially compromising guest system integrity.

MediumCVSS 5.9Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a firmware-level AMD Secure Processor issue affecting listed AMD EPYC and EPYC Embedded platforms. An attacker already holding local administrative privileges may alter MMIO routing, which could compromise guest system integrity on virtualized systems. It is not described as remote or unauthenticated.

Executive priority

Treat this as a moderate-priority firmware remediation item for AMD-based virtualization infrastructure. It requires existing high privilege, but the possible guest integrity impact makes it important for shared, regulated, or high-trust hosting environments.

Technical view

CVE-2025-54510 is a CWE-414 missing lock verification flaw in AMD Secure Processor firmware. The CVSS 4.0 score is 5.9, with local attack vector and high privileges required. The stated security impact is high integrity impact to subsequent systems, specifically guest system integrity.

Likely exposure

Exposure is most likely on servers or embedded platforms using the listed AMD EPYC 7003, 8004, 9004, 9005, or EPYC Embedded firmware versions. Virtualization hosts deserve special attention because the stated impact concerns guest integrity.

Exploitation context

The bundle provides no evidence of active exploitation, and KEV status is false. Exploitation requires local authenticated administrative privileges, which reduces broad internet risk but matters if an attacker compromises a host administrator account or privileged management path.

Researcher notes

The public bundle does not include exploit details or a named fixed firmware version. Analysis should stay anchored to AMD-SB-3034, CVE metadata, OEM firmware releases, and host privilege boundaries. Avoid assuming affected scope beyond the listed products and versions.

Mitigation direction

  • Check AMD-SB-3034 and server OEM guidance for firmware updates.
  • Apply vendor-provided BIOS, UEFI, or ASP firmware updates when available.
  • Prioritize virtualization hosts running affected EPYC firmware versions.
  • Restrict and monitor local administrative access to affected hosts.
  • Review cloud or hosting provider notices for managed infrastructure exposure.

Validation and detection

  • Inventory AMD EPYC and EPYC Embedded processor models in server fleets.
  • Record platform firmware or PI versions from OEM management tooling.
  • Compare observed versions against the affected versions in the CVE bundle.
  • Identify systems hosting untrusted or high-value guest workloads.
  • Confirm remediation status using AMD and OEM advisory documentation.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-414: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-54510 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.9 (4.0)
Known Exploited
No
Published

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.9CVSS 4.0MediumCVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:NAMD

Vulnerability scoring details

Base CVSS 4.0 score

5.9Medium
CVSS 4.0 vector shape for CVE-2025-54510Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMDAMD EPYC™ 9004 Series ProcessorsGenoaPI_1.0.0.Haffected
AMDAMD EPYC™ 7003 Series ProcessorsMilanPI-SP3_1.0.0.Jaffected
AMDAMD EPYC™ 9005 Series ProcessorsTurinPI_1.0.0.8affected
AMDAMD EPYC™ 8004 Series ProcessorsGenoaPI_1.0.0.Haffected
AMDAMD EPYC™ Embedded 7003 Series ProcessorsEmbMilanPI-SP3 1.0.0.Daffected
AMDAMD EPYC™ Embedded 9004 Series ProcessorsEmbGenoaPI-SP5 1.0.0.Daffected
AMDAMD EPYC™ Embedded 9004 Series ProcessorsEmbGenoaPI-SP5 1.0.0.Daffected
AMDAMD EPYC™ Embedded 8004 Series ProcessorsEmbGenoaPI-SP5 1.0.0.Daffected
AMDAMD EPYC™ Embedded 9005 Series ProcessorsEmbeddedTurinPI_SP5_1004affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-414 · source CWE mapping

Missing Lock Check

Missing Lock Check represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.