CVE-2025-0038
CVE-2025-0038
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.6EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →