Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resulting in unauthorized access to privileged resources and loss of confidentiality.
Metrics
Affected Vendors & Products
References
History
Thu, 14 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper privilege management in KVM key download allowing token swapping and key theft |
Thu, 14 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resulting in unauthorized access to privileged resources and loss of confidentiality. | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2026-05-14T15:35:04.518Z
Reserved: 2025-10-16T20:46:13.455Z
Link: CVE-2025-62625
Updated: 2026-05-14T15:35:00.158Z
Status : Awaiting Analysis
Published: 2026-05-14T15:16:43.957
Modified: 2026-05-14T15:53:24.703
Link: CVE-2025-62625
No data.
OpenCVE Enrichment
Updated: 2026-05-14T16:30:24Z