The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
History

Wed, 14 Jan 2026 19:00:00 +0000

Type Values Removed Values Added
Description The security state of the calling processor into ArmĀ® Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC. The security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

Tue, 25 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd kria Som
Amd zynq Ultrascale+
Arm
Arm trusted Firmware-a
Vendors & Products Amd
Amd kria Som
Amd zynq Ultrascale+
Arm
Arm trusted Firmware-a

Mon, 24 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 23 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Description The security state of the calling processor into ArmĀ® Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.
Weaknesses CWE-1284
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published: 2025-11-23T17:07:56.914Z

Updated: 2026-01-14T18:34:46.969Z

Reserved: 2025-05-22T16:34:02.896Z

Link: CVE-2025-48507

cve-icon Vulnrichment

Updated: 2025-11-24T14:35:43.739Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-23T17:15:47.773

Modified: 2026-01-14T19:16:44.873

Link: CVE-2025-48507

cve-icon Redhat

No data.