Home

Description

Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.

PUBLISHED Reserved 2025-10-04 | Published 2026-05-13 | Updated 2026-05-14 | Assigner AMD




HIGH: 8.5CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Problem types

CWE-1233 Security-Sensitive Hardware Controls with Missing Lock Bit Protection

Product status

Default status
affected

GenoaPI_1.0.0.H
unaffected

Default status
affected

TurinPI_1.0.0.8
unaffected

Default status
affected

GenoaPI_1.0.0.H
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.D
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.D
unaffected

Default status
affected

EmbGenoaPI-SP5 1.0.0.D
unaffected

Default status
affected

EmbeddedTurinPI_SP5_1004
unaffected

References

www.amd.com/...es/product-security/bulletin/AMD-SB-3030.html

cve.org (CVE-2025-61972)

nvd.nist.gov (CVE-2025-61972)

Download JSON