Junglewise Threat Intelligence

CVE-2025-0040: AMD Processor improper access control in JTAG and AXI interface

CVE-2025-0040 · Severity: info · CVSS 5.3 · Published 2026-05-15

Technologies: Amd Processors. Vendors: Amd.

Executive brief

A security vulnerability in certain AMD hardware components could allow an individual with physical access to the device to bypass security controls. By interacting with the chip's debugging interface, an attacker could read or modify sensitive internal data. This could lead to the theft of confidential information or the compromise of the system's integrity.

Technical details

An improper access control vulnerability exists in the interface between the Joint Test Action Group (JTAG) and the Advanced Extensible Interface (AXI) on affected AMD hardware. A physical attacker can exploit this flaw to access cross-chip debug (XCD) registers, which are typically restricted. Successful exploitation allows for the reading or overwriting of these registers, potentially compromising data confidentiality and integrity. The attack requires physical access and is characterized by high complexity and specific timing/environmental conditions (as indicated by the CVSS 4.0 AC:H/AT:P metrics).

Affected products

  • AMD Processors

Timeline

  • 2026-05-15: disclosed: Initial NVD publication date

References

Related threats