CVE-2025-48507 Details
Description
The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
A vulnerability exists in the Arm Trusted Firmware (TF-A) used by AMD's Zynq UltraScale+ System on Chips (SoCs), including MPSoCs, RFSoCs, and Kria SOMs. The issue arises because the security state of the calling processor is not properly utilized, potentially allowing non-secure processors to access secure memory, perform cryptographic operations, and control various subsystems within the SoC.
AMD plans to address this vulnerability in the upcoming 2025.2 release, scheduled for November 15, 2025. This update will ensure that the security state information from Arm Cortex-A processors is communicated to the PMU firmware, allowing for proper operation authorization.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 23, 2025CISA-ADP
Assessed Nov 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8017.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1284 | Improper Validation of Specified Quantity in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Arm Trusted Firmware | All versions |
CPE
Remediation
| |
| AMD Kria SOM | All versions |
CPE
Remediation
| |
| AMD Zynq UltraScale+ MPSoCs | All versions |
CPE
Remediation
| |
| AMD Zynq UltraScale+ RFSoCs | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | CVE Modified | [email protected] |
| Nov 23, 2025 | New CVE Received | [email protected] |
Volerion