Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amd
Amd epyc 7003 Series Processors Amd epyc 8004 Series Processors Amd epyc 9004 Series Processors Amd epyc 9005 Series Processors Amd epyc Embedded 7003 Series Processors Amd epyc Embedded 8004 Series Processors Amd epyc Embedded 9004 Series Processors Amd epyc Embedded 9005 Series Processors |
|
| Vendors & Products |
Amd
Amd epyc 7003 Series Processors Amd epyc 8004 Series Processors Amd epyc 9004 Series Processors Amd epyc 9005 Series Processors Amd epyc Embedded 7003 Series Processors Amd epyc Embedded 8004 Series Processors Amd epyc Embedded 9004 Series Processors Amd epyc Embedded 9005 Series Processors |
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality. | |
| Weaknesses | CWE-1220 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: AMD
Published: 2026-02-10T19:14:22.874Z
Updated: 2026-02-11T14:54:00.307Z
Reserved: 2025-05-22T16:34:07.747Z
Link: CVE-2025-48514
Updated: 2026-02-11T14:53:54.901Z
Status : Awaiting Analysis
Published: 2026-02-10T20:16:45.097
Modified: 2026-02-10T21:51:48.077
Link: CVE-2025-48514
No data.