CVE-2025-48515
Last modified
CVE-2025-48515 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Insufficient parameter sanitization in AMD Secure Processor (ASP) Boot Loader could allow an attacker with access to SPIROM upgrade to overwrite the memory, potentially resulting in arbitrary code execution.
Metrics
CVSS:4.0/AV:P/AC:H/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-48515?
How severe is CVE-2025-48515?
How do I fix CVE-2025-48515?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4851A vulnerability classified as critical was found in TOTOLINK…9.8
- CVE-2025-48510Improper return value within AMD uProf can allow a local att…7.1
- CVE-2025-48511Improper input validation within AMD uprof can allow a local…5.5
- CVE-2025-48512Incorrect default permissions in the installation directory …7
- CVE-2025-48513Use of uninitialized resource within the AMD Platform Manage…6.9
- CVE-2025-48514Insufficient Granularity of Access Control in SEV firmware c…4
- CVE-2025-48516Insecure default configuration state of DDR5 memory module b…6.9
- CVE-2025-48517Insufficient Granularity of Access Control in SEV firmware c…4.6
- CVE-2025-48518Improper input validation in AMD Graphics Driver could allow…6.9
- CVE-2025-48519An improper input validation vulnerability within the AMD Pl…8.5
- CVE-2025-4852A vulnerability, which was classified as problematic, has be…3.4
- CVE-2025-48520An improper input validation vulnerability within the AMD Pl…6.9
Are you affected by CVE-2025-48515?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
