« Volver al listado

CVE-2025-0036

Estado: AplazadaBaja (3.2)—

In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0036",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0036",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-10T14:19:45.871057Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@amd.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 3.2,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "Versal Adaptive SoC Devices",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal RF Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal AI Edge Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal Prime Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal Premium Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal AI Core Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Versal HBM Series",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "Alveo V80 Compute Accelerator",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.1 release"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-06-10T00:15:21.197",
  "references": [
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8011.html",
      "source": "psirt@amd.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@amd.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-497"
        },
        {
          "lang": "en",
          "value": "CWE-682"
        },
        {
          "lang": "en",
          "value": "CWE-772"
        },
        {
          "lang": "en",
          "value": "CWE-940"
        },
        {
          "lang": "en",
          "value": "CWE-941"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data."
    },
    {
      "lang": "es",
      "value": "En los dispositivos SoC AMD Versal Adaptive, la configuración incorrecta del SSS durante las operaciones criptográficas en tiempo de ejecución (post arranque) podría provocar que los datos se escriban y lean incorrectamente desde ubicaciones no válidas, además de devolver datos criptográficos incorrectos."
    }
  ],
  "lastModified": "2026-06-17T08:25:42.213",
  "sourceIdentifier": "psirt@amd.com"
}