CVE-2025-48516

MEDIUM

Amd Ryzen™ 4000 Series Mobile Processors With Radeon™ Graphics - Incorrect Default Permissions

Title source: rule
STIX 2.1

Description

Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module.

Scores

CVSS v4 6.9
EPSS 0.0001
EPSS Percentile 3.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (34)
AMD/AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics No fix planned
AMD/AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics No fix planned
AMD/AMD Ryzen™ 3000 Series Desktop Processors No fix planned
AMD/AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics No fix planned
AMD/AMD Ryzen™ 4000 Series Desktop Processors No fix planned
AMD/AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics No fix planned
AMD/AMD Ryzen™ 5000 Series Desktop Processors No fix planned
AMD/AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics No fix planned
AMD/AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics No fix planned
AMD/AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics No fix planned
... and 24 more
Published May 15, 2026
Tracked Since May 15, 2026