CVE-2025-48514: AMD Epyc 7003 Series Processors
Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.
Affected products
- AMD AMD Epyc 7003 Series Processors
- AMD AMD Epyc 8004 Series Processors
- AMD AMD Epyc 9004 Series Processors
- AMD AMD Epyc 9005 Series Processors
- AMD AMD Epyc Embedded 7003 Series Processors
- AMD AMD Epyc Embedded 8004 Series Processors
- AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Bergamo
- AMD AMD Epyc Embedded 9004 Series Processors Formerly Codenamed Genoa
- AMD AMD Epyc Embedded 9005 Series Processors
Published 2026-02-10. Last modified 2026-06-17.