CVE-2025-62862
Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process running in Non-Secure state or (2) an out-of-bounds write which corrupts Secure or Non-Secure memory, limited to memory mapped to UEFI-MM Secure Partition by the Secure Partition Manager.
Published:Dec 16, 2025
Last Modified:Dec 31, 2025
EPS:Dec 16, 2025
EPSS Score:0.00016
CVSS Score:4.6
Affected Products
Vendor
Product
Action
Vendor
Amperecomputing
Product
Ampereone A128-34x
Amperecomputing
Ampereone A128-34x
Vendor
Amperecomputing
Product
Ampereone A128-34x Firmware
Amperecomputing
Ampereone A128-34x Firmware
Vendor
Amperecomputing
Product
Ampereone A144-24x
Amperecomputing
Ampereone A144-24x
Vendor
Amperecomputing
Product
Ampereone A144-24x Firmware
Amperecomputing
Ampereone A144-24x Firmware
Vendor
Amperecomputing
Product
Ampereone A144-26m
Amperecomputing
Ampereone A144-26m
Vendor
Amperecomputing
Product
Ampereone A144-26m Firmware
Amperecomputing
Ampereone A144-26m Firmware
Vendor
Amperecomputing
Product
Ampereone A144-27x
Amperecomputing
Ampereone A144-27x
Vendor
Amperecomputing
Product
Ampereone A144-27x Firmware
Amperecomputing
Ampereone A144-27x Firmware
Vendor
Amperecomputing
Product
Ampereone A144-33m
Amperecomputing
Ampereone A144-33m
Vendor
Amperecomputing
Product
Ampereone A144-33m Firmware
Amperecomputing
Ampereone A144-33m Firmware
Vendor
Amperecomputing
Product
Ampereone A160-28m
Amperecomputing
Ampereone A160-28m
Vendor
Amperecomputing
Product
Ampereone A160-28m Firmware
Amperecomputing
Ampereone A160-28m Firmware
Vendor
Amperecomputing
Product
Ampereone A160-28x
Amperecomputing
Ampereone A160-28x
Vendor
Amperecomputing
Product
Ampereone A160-28x Firmware
Amperecomputing
Ampereone A160-28x Firmware
Vendor
Amperecomputing
Product
Ampereone A192-26m
Amperecomputing
Ampereone A192-26m
Vendor
Amperecomputing
Product
Ampereone A192-26m Firmware
Amperecomputing
Ampereone A192-26m Firmware
Vendor
Amperecomputing
Product
Ampereone A192-26x
Amperecomputing
Ampereone A192-26x
Vendor
Amperecomputing
Product
Ampereone A192-26x Firmware
Amperecomputing
Ampereone A192-26x Firmware
Vendor
Amperecomputing
Product
Ampereone A192-32m
Amperecomputing
Ampereone A192-32m
Vendor
Amperecomputing
Product
Ampereone A192-32m Firmware
Amperecomputing
Ampereone A192-32m Firmware
Vendor
Amperecomputing
Product
Ampereone A192-32x
Amperecomputing
Ampereone A192-32x
Vendor
Amperecomputing
Product
Ampereone A192-32x Firmware
Amperecomputing
Ampereone A192-32x Firmware
Vendor
Amperecomputing
Product
Ampereone A96-36m
Amperecomputing
Ampereone A96-36m
Vendor
Amperecomputing
Product
Ampereone A96-36m Firmware
Amperecomputing
Ampereone A96-36m Firmware
Vendor
Amperecomputing
Product
Ampereone A96-36x
Amperecomputing
Ampereone A96-36x
Vendor
Amperecomputing
Product
Ampereone A96-36x Firmware
Amperecomputing
Ampereone A96-36x Firmware
Vendor
Amperecomputing
Product
Amperone
Amperecomputing
Amperone
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
