Impact
The vulnerability is an out‑of‑bounds read in the power management firmware that can be triggered by a local attacker with low privileges. This flaw belongs to CWE‑125 and could expose sensitive data from adjacent memory and disrupt power‑management functionality, leading to a partial loss of confidentiality and some availability issues. Attackers would be able to read data they should not have access to and possibly cause erratic behavior of graphics or CPU components.
Affected Systems
Affected are a range of AMD hardware, including Radeon Pro W7000 and RX 7000 series graphics cards, Ryzen 7040 mobile processors with Radeon Graphics, Ryzen 8000 and 8040 desktop and mobile processors, Ryzen AI 300 and Al Max+ processors, and the Ryzen Embedded 8000 series. Any system using the power‑management firmware on these devices is susceptible.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and no EPSS score is available, meaning the exploitation probability cannot be quantified from public data. The vulnerability is not listed in the CISA KEV catalog. Because the attack vector is local and requires low‑privileged access, an attacker would need proximity to the device and is limited to firmware interactions. The impact is limited to partial confidentiality and availability, so while the risk is moderate, the threat is non‑critical compared to higher‑severity issues.
OpenCVE Enrichment