Impact
The vulnerability is caused by an uninitialized resource in the AMD Platform Management Framework, which can be leveraged by an attacker to read kernel memory that has not been properly initialized. This flaw is classified as CWE-908 and can result in the disclosure of sensitive data or disruption of system availability if kernel memory contents are corrupted or improperly accessed.
Affected Systems
The affected products are AMD Ryzen series processors, including the 6000, 7035, 7040 Mobile, 8040 Mobile, Embedded 8000, and Z1 series. Versions of the Platform Management Framework onto which this flaw applies are not explicitly listed in the data, so any system running these processor families should be evaluated against the AMD security bulletin.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires exploiting the Platform Management Framework, which may demand local privileges or access to the management interface. The absence of a stated exploitation path suggests that an attacker would need either physical or privileged remote access to the system’s management controllers to read uninitialized kernel memory.
OpenCVE Enrichment