
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54514 is an improper isolation of shared resources on a System-on-Chip (SoC) vulnerability affecting multiple AMD processor families. A malicious local attacker with elevated privileges could exploit this flaw to cause a partial loss of integrity. The vulnerability was discovered internally by AMD and publicly disclosed on February 10, 2026, as part of two AMD security bulletins (AMD-SB-3023 and AMD-SB-4013). It carries a CVSS v4.0 base score of 4.8 (Medium) (AMD SB-3023, AMD SB-4013).
The vulnerability is classified under CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip), which occurs when hardware components on a SoC do not adequately isolate shared resources between different privilege domains or execution contexts. An attacker with local access and at least low-level privileges can exploit this flaw to manipulate shared SoC resources in a way that partially compromises system integrity. No user interaction is required, and the attack complexity is low, though the impact is limited to a partial integrity loss with no confidentiality or availability impact. The vulnerability was found internally by AMD during security audits (AMD SB-3023, AMD SB-4013).
Successful exploitation of CVE-2025-54514 results in a partial loss of integrity on the affected system, with no impact to confidentiality or availability. The attack is confined to the local attack surface and requires an attacker who already has at least low-privilege local access to the system. Given the limited scope — no lateral movement potential and no data exposure risk — the practical impact is constrained, though it could be chained with other vulnerabilities in a multi-stage attack against AMD-based platforms (AMD SB-3023, AMD SB-4013).
There is no public evidence of in-the-wild exploitation of CVE-2025-54514, and no public proof-of-concept exploit code has been identified. The EPSS score is very low at approximately 0.014%, reflecting a minimal probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least low privileges, which significantly limits the attacker pool (AMD SB-3023).
AMD has released Platform Initialization (PI) firmware updates to address CVE-2025-54514 across multiple product lines. Key mitigations include:
Users should contact their OEM for the specific BIOS update applicable to their product. No configuration-based workaround is documented for this CVE (AMD SB-3023, AMD SB-4013).
AMD disclosed CVE-2025-54514 as part of two coordinated security bulletins (AMD-SB-3023 and AMD-SB-4013) published on February 10, 2026, covering a broad set of EPYC, Ryzen, and Athlon processor vulnerabilities. The vulnerability was identified internally by AMD, and no external researcher credit is listed for this specific CVE. Community and media reaction has been limited given the moderate severity and local-only attack vector, with aggregator sites such as VulDB and CVEFeed.io tracking the disclosure without notable commentary (AMD SB-3023, AMD SB-4013).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."