AMD EPYC 7002
cpe:2.3:h:amd:epyc_7002:*:*:*:*:*:*:*, +1 more
A vulnerability exists in the Secure Encrypted Virtualization (SEV) firmware of AMD EPYC processors, specifically in the 9004 and embedded 9004 series, due to insufficient granularity of access control. This flaw could allow a privileged attacker to create a SEV-ES guest that could attack a SEV-SNP guest, potentially leading to a loss of confidentiality. The vulnerability affects several different versions and ranges of AMD EPYC processors, including the 7001, 7002, 7003, 8004, 9004, and embedded 9004 series.
Exploitation of this vulnerability could result in a loss of confidentiality for memory associated with a SEV-SNP guest.
Users are advised to update to the AMD EPYC Platform Initialization (PI) or Secure Encrypted Virtualization (SEV) firmware version that includes the mitigation. For AMD EPYC 9004 series processors, the relevant PI version is 'GenoaPI 1.0.0.H' or 'TurinPI 1.0.0.6', both of which include the necessary SEV firmware update. For AMD EPYC embedded 9004 series processors, the recommended version is 'EmbGenoaPI-SP5 1.0.0.C', also available starting October 31, 2025.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.