Improper Access Control Vulnerability in AMD Products
CVE-2025-0040

5.3MEDIUM

What is CVE-2025-0040?

An improper access control vulnerability exists within the interaction between the Joint Test Action Group (JTAG) and the Advanced Extensible Interface (AXI) in several AMD products. This could potentially allow an attacker with physical access to exploit this weakness, enabling them to read or modify the contents of cross-chip debug (XCD) registers. Such unauthorized access may lead to serious security concerns, including loss of data integrity and confidentiality, underscoring the importance of safeguarding physical access to affected devices.

Affected Version(s)

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics PhoenixPI-FP8-FP7_1.2.0.B

AMD Ryzen™ 8000 Series Desktop Processors ComboAM5PI 1.2.0.3d

AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics PhoenixPI-FP8-FP7_1.2.0.B

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.