Data Integrity and Confidentiality Issue in PCI Express Products by PCI-SIG
CVE-2025-9613

6.5MEDIUM

What is CVE-2025-9613?

A vulnerability in the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification reveals concerns over insufficient guidance related to tag reuse after completion timeouts. This oversight may lead to multiple outstanding Non-Posted Requests utilizing the same tag, creating a tag aliasing situation. Such conditions can jeopardize the correct delivery of completions to appropriate security contexts, posing risks to both data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PCI Express Integrity and Data Encryption (PCIe IDE) Specification 0 < 7.1-Rev7.0

PCI Express Integrity and Data Encryption (PCIe IDE) Specification 0 < 6.5-Rev7.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.