Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensitive keys, potentially leading to loss of confidentiality.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensitive keys, potentially leading to loss of confidentiality. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-05-14T15:35:55.110Z
Reserved: 2025-10-16T20:46:13.454Z
Link: CVE-2025-62619
Updated: 2026-05-14T15:35:50.855Z
Status : Awaiting Analysis
Published: 2026-05-14T15:16:43.147
Modified: 2026-05-14T15:53:24.703
Link: CVE-2025-62619
No data.
OpenCVE Enrichment
Updated: 2026-05-14T16:30:24Z