CVE-2025-62864: Critical severity Ampere AmpereOne AC03 vulnerability
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62864?
CVE-2025-62864 is a high-severity vulnerability due to the potential for an out-of-bounds write in the UEFI-MM Secure Partition.
How do I fix CVE-2025-62864?
To address CVE-2025-62864, upgrade the affected AmpereOne AC03 devices to version 3.5.9.3 or later, AC04 devices to version 4.4.5.2 or later, and AmpereOne M devices to version 5.4.5.1 or later.
What devices are affected by CVE-2025-62864?
CVE-2025-62864 affects AmpereOne AC03, AC04, and M devices prior to their respective fixed versions.
What could happen if CVE-2025-62864 is exploited?
Exploitation of CVE-2025-62864 could lead to unauthorized access or manipulation of memory, potentially compromising device security.
When was CVE-2025-62864 disclosed?
CVE-2025-62864 was disclosed as part of ongoing security assessments for Ampere products.