Ampereone A192 32m FirmwareOperating system · Amperecomputing

CVE-2025-62864

CRITICAL · 9.8 CVSS v3.1 Published 2025-12-16
Fix available
A fix is available. Upgrade to 4.4.5.2 / 5.4.5.1 or later.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

A memory corruption vulnerability exists in the UEFI-MM (Management Mode) secure partition of AmpereOne AC03, AC04, and M processors where an incorrectly formed SMC (Secure Monitor Call) to the MMCommunicate service triggers an out-of-bounds write, potentially allowing code execution in the secure firmware context.

MitigationApply vendor-supplied firmware updates to patched versions (AC03: 3.5.9.3+, AC04: 4.4.5.2+, M: 5.4.5.1+) through the appropriate BMC/IPMI or UEFI flash mechanism; verify firmware integrity post-update.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Ampereone A192 32m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A192 26m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A160 28m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A144 33m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A144 26m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A96 36m FirmwareOperating system
Affected:< 5.4.5.1
Ampereone A96 36x FirmwareOperating system
Affected:< 4.4.5.2
Ampereone A128 34x FirmwareOperating system
Affected:< 4.4.5.2

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Identify AmpereOne processor model
    Check system hardware inventory via BMC/IPMI: `ipmitool fru print` or `dmidecode -t processor` to find the processor part number (e.g., A192, A160, A144, A96, A128)
    Affected if Processor is not an AmpereOne AC03, AC04, or M variant (not affected)
  2. Retrieve current firmware version
    Query BMC or UEFI for firmware version: `ipmitool mc info` or check BMC web interface under Firmware/BIOS version. For AmpereOne, firmware version format is X.Y.Z.W
    Affected if Cannot retrieve firmware version from BMC (further investigation needed)
  3. Compare firmware version against affected ranges
    Match your firmware version to the affected list: A192/A160/A144/A96 36m versions < 5.4.5.1 are affected; A96 36x/A128 34x versions < 4.4.5.2 are affected
    Affected if Firmware version is lower than the patched version for your specific processor model
  4. Verify MMCommunicate service accessibility
    This is an internal UEFI-MM secure partition service. The vulnerability exists in how the secure monitor handles malformed SMC calls to MMCommunicate. No external check required as this is a code-level flaw in the firmware itself
    Affected if Not applicable - this is a passive condition; the flaw is present if firmware version is in affected range

Your environment is affected if you are running an AmpereOne AC03, AC04, or M processor with firmware version below 5.4.5.1 (for A192/A160/A144/A96 36m) or below 4.4.5.2 (for A96 36x/A128 34x).

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 4.4.5.2 / 5.4.5.1 or later
Fixed in 4.4.5.25.4.5.1
Interim mitigation

Apply vendor-supplied firmware updates to patched versions (AC03: 3.5.9.3+, AC04: 4.4.5.2+, M: 5.4.5.1+) through the appropriate BMC/IPMI or UEFI flash mechanism; verify firmware integrity post-update.

Recommended fix High confidence

For AmpereOne A192 32m, A192 26m, A160 28m, A144 33m, A144 26m, A96 36m: upgrade to firmware 5.4.5.1 or later. For AmpereOne A96 36x and A128 34x: upgrade to firmware 4.4.5.2 or later

  1. 1. Identify the exact AmpereOne model and current firmware version running on the affected system
  2. 2. Download the latest firmware update from amperecomputing.com for the specific AmpereOne model
  3. 3. Review Ampere's firmware update documentation and ensure the system is in a state where a firmware update can be safely performed (e.g., stable power, proper backup)
  4. 4. Apply the firmware update using the vendor-provided update mechanism (typically via BMC/IPMI or dedicated firmware update utility)
  5. 5. After updating, verify the firmware version has been successfully updated to the fixed release
  6. 6. Confirm the system boots normally and all services are operational
Caveat Firmware updates carry inherent risk and should be performed with proper backup and rollback planning; ensure compatibility with existing system configuration

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Ampereone A192 32m Firmware Scoped from the published advisory
  • Consultation4.0 h
  • Implementation8.0 h
  • Testing4.0 h
  • Review / QA2.0 h
18.0 hours of engineering $3,200
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $5,120.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2025-62864 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2025-62864 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data