CVE-2025-54515 is a low-severity vulnerability affecting Versal Adaptive SoC's Trusted Firmware for Cortex-A processors (TF-A). The vulnerability stems from an incorrect secure flag setting for Arm's Power State Coordination Interface (PSCI) commands, causing non-secure processor requests to appear as if they originated from a secure state. The CVSS score of 1.0 indicates a low impact, with a local attack vector, low attack complexity, and potential for limited availability impact. The FAUCET Risk Score is 6/100, and the EPSS score is very low, suggesting minimal exploitability. Currently, there is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, further indicating its low profile and limited immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | Alveo™ V80 Compute Accelerator | Range not provided by sourceCNA affecteddefault affected | |
| AMD | Versal™ AI Core Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | Versal™ AI Edge Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | Versal™ HBM Series | Range not provided by sourceCNA affecteddefault affected | |
| AMD | Versal™ Premium Series | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.