CVE-2025-9612 describes a vulnerability within the PCI Express (PCIe) Integrity and Data Encryption (IDE) specification, stemming from insufficient guidance on Transaction Layer Packet (TLP) ordering and tag uniqueness. This flaw primarily affects products implementing the pcisig pci_express_integrity_and_data_encryption specification, including Intel and AMD processors. With a CVSS score of 5.1 (Medium), the vulnerability allows local or physical attackers on the PCIe bus to replay or reorder encrypted packets without detection, potentially violating data integrity. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules available, the vulnerability has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:pcisig:pci_express_integrity_and_data_encryption:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.