In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.
CVE ID: CVE-2025-0037
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.6
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Vendor: AMD
Product: Platform Loader and Manager (PLM)
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.98% (scored less or equal to compared to others)
EPSS Date: 2025-06-13 (when was this score calculated)