CVE-2025-62864
Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.
NVD · uneditedAmpere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.
Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.
dbcve analysis · high confidenceA memory corruption vulnerability exists in the UEFI-MM (Management Mode) secure partition of AmpereOne AC03, AC04, and M processors where an incorrectly formed SMC (Secure Monitor Call) to the MMCommunicate service triggers an out-of-bounds write, potentially allowing code execution in the secure firmware context.
Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.
Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.
NVD · CPE data< 5.4.5.1< 5.4.5.1< 5.4.5.1< 5.4.5.1< 5.4.5.1< 5.4.5.1< 4.4.5.2< 4.4.5.2CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.
From the vector- Attack vector
- Network
- Complexity
- Low
- Privileges
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.
dbcve checksWork through these to decide whether this CVE applies to you.
-
Identify AmpereOne processor modelCheck system hardware inventory via BMC/IPMI: `ipmitool fru print` or `dmidecode -t processor` to find the processor part number (e.g., A192, A160, A144, A96, A128)Affected if Processor is not an AmpereOne AC03, AC04, or M variant (not affected)
-
Retrieve current firmware versionQuery BMC or UEFI for firmware version: `ipmitool mc info` or check BMC web interface under Firmware/BIOS version. For AmpereOne, firmware version format is X.Y.Z.WAffected if Cannot retrieve firmware version from BMC (further investigation needed)
-
Compare firmware version against affected rangesMatch your firmware version to the affected list: A192/A160/A144/A96 36m versions < 5.4.5.1 are affected; A96 36x/A128 34x versions < 4.4.5.2 are affectedAffected if Firmware version is lower than the patched version for your specific processor model
-
Verify MMCommunicate service accessibilityThis is an internal UEFI-MM secure partition service. The vulnerability exists in how the secure monitor handles malformed SMC calls to MMCommunicate. No external check required as this is a code-level flaw in the firmware itselfAffected if Not applicable - this is a passive condition; the flaw is present if firmware version is in affected range
Your environment is affected if you are running an AmpereOne AC03, AC04, or M processor with firmware version below 5.4.5.1 (for A192/A160/A144/A96 36m) or below 4.4.5.2 (for A96 36x/A128 34x).
Generated from the published advisory. Verify against your own configuration.
Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.
dbcve · scoped4.4.5.25.4.5.1
Apply vendor-supplied firmware updates to patched versions (AC03: 3.5.9.3+, AC04: 4.4.5.2+, M: 5.4.5.1+) through the appropriate BMC/IPMI or UEFI flash mechanism; verify firmware integrity post-update.
For AmpereOne A192 32m, A192 26m, A160 28m, A144 33m, A144 26m, A96 36m: upgrade to firmware 5.4.5.1 or later. For AmpereOne A96 36x and A128 34x: upgrade to firmware 4.4.5.2 or later
- 1. Identify the exact AmpereOne model and current firmware version running on the affected system
- 2. Download the latest firmware update from amperecomputing.com for the specific AmpereOne model
- 3. Review Ampere's firmware update documentation and ensure the system is in a state where a firmware update can be safely performed (e.g., stable power, proper backup)
- 4. Apply the firmware update using the vendor-provided update mechanism (typically via BMC/IPMI or dedicated firmware update utility)
- 5. After updating, verify the firmware version has been successfully updated to the fixed release
- 6. Confirm the system boots normally and all services are operational
Generated from the published advisory — verify against the referenced sources before acting.
- Consultation4.0 h
- Implementation8.0 h
- Testing4.0 h
- Review / QA2.0 h
An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,120.
Scan for this in your stack
Free · runs locallyCheck whether your project pulls in CVE-2025-62864 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.
References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.
Primary sourcesPractitioner notes
ContributedPeer-ranked notes from engineers who’ve handled CVE-2025-62864 in production — separate from our analysis above.
The advisory tells you what broke. It rarely tells you what actually worked. If you’ve dealt with this one, that detail is what the next engineer is searching for.
- The version that genuinely resolved it — not the one the vendor claimed
- A config change or rule that shut the vector down
- A gotcha in the upgrade path that cost you an afternoon
No notes yet
Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.
A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.
- Verified mitigations, workarounds, and config changes
- Version or environment caveats, and links to real fixes
- No weaponised exploit code, or anything meant to cause harm
- No spam, self-promotion, credentials, or personal data