Missing Authentication in KVM Key Download Endpoint Affecting AMD Products
CVE-2025-62619

6.3MEDIUM

What is CVE-2025-62619?

A security flaw exists in the KVM key download endpoint of AMD's Key Management System, where the lack of adequate authentication measures allows unauthenticated attackers to access sensitive keys. This exposure, if exploited, could lead to significant confidentiality breaches, as attackers with knowledge of the vulnerable URL could potentially retrieve sensitive cryptographic keys, undermining the integrity of systems relying on those keys.

Affected Version(s)

AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics AMD Device Management Portal 3.0.0.895

AMD Device Management Portal (ADMP) 3.0.0.895

AMD Ryzen™ 3000 Series Desktop Processors AMD Device Management Portal 3.0.0.895

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.