CVE Details

000039030 - Design Advisory for Zynq UltraScale+: Missing Use of the Secure Flag in Zynq UltraScale+ SoC Trusted Firmware

Release Date
2025-12-17
Revision
1.0 English

 

CVE

CVE Description

CVSS Score

CVE-2025-48507

The security state of the calling processor into Trusted Firmware for Cortex-A processors (TF-A) is not used and could potentially allow non-secure processors to have access to secure memories, access to crypto operations, and the ability to turn on and off subsystems within the SOC.

8.6 (High)

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H