Impact
An insufficient boundary check in the USB boot mode of AMD Versal Adaptive SoC devices can be triggered when the mode is enabled through board modifications. Crafted images loaded during boot may overflow a buffer and overwrite an active function pointer, enabling arbitrary code execution. The attacker could then subvert confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects AMD Alveo Accelerator Cards and several Versal Adaptive SoC families, including the Versal Premium, Prime, RF, AI Core, AI Edge, HBM, and Versal Premium Series Gen 2 (2VP3402, 2VP3502, 2VP3602). No specific firmware or hardware revisions are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score is not available, suggesting uncertainty about exploit frequency. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the USB boot process; an attacker would need to supply a crafted image and have physical or board‑based access to enable USB boot mode.
OpenCVE Enrichment