Impact
Improper access control for the IOMMU register interface could allow a privileged attacker to trigger non-coherent accesses by the AMD Secure Processor, potentially resulting in loss of integrity. The flaw is a missing authorization check that permits manipulation of registers beyond intended bounds. This failure is classified as CWE-1262, reflecting an access‑control weakness. The consequence is limited to data integrity loss; no known path to code execution.
Affected Systems
AMD EPYC 8004 and 9004 series processors, AMD EPYC 9005 series processors, and their embedded equivalents (8004, 9004, 9005). All affected silicon and firmware that implement the IOMMU register interface are vulnerable unless patched.
Risk and Exploitability
The CVSS score of 4 indicates low severity. The EPSS score is < 1%, indicating a low probability of exploitation. The lack of a KEV designation suggests no publicly known exploits. Based on the description, it is inferred that the attacker would need privileged access to modify IOMMU registers, implying a local privilege escalation scenario. Once a privileged attacker triggers non-coherent accesses, the integrity of data processed by the AMD Secure Processor may be compromised.
OpenCVE Enrichment