CVE-2025-62864

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM MMCommunicate service that could result in an out-of-bounds write within the UEFI-MM Secure Partition context.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a192-32m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a192-32m:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a192-26m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a192-26m:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a160-28m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a160-28m:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a144-33m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a144-33m:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a144-26m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a144-26m:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a96-36m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a96-36m:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a96-36x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a96-36x:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a128-34x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a128-34x:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a144-24x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a144-24x:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a144-27x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a144-27x:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a160-28x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a160-28x:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a192-26x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a192-26x:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a192-26x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a192-26x:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amperecomputing:ampereone_a192-32x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amperecomputing:ampereone_a192-32x:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-16 18:16

Updated : 2026-01-13 20:58


NVD link : CVE-2025-62864

Mitre link : CVE-2025-62864

CVE.ORG link : CVE-2025-62864


JSON object : View

Products Affected

amperecomputing

  • ampereone_a160-28x_firmware
  • ampereone_a144-24x_firmware
  • ampereone_a192-32x
  • ampereone_a128-34x
  • ampereone_a144-26m
  • ampereone_a96-36m
  • ampereone_a144-27x_firmware
  • ampereone_a192-26m
  • ampereone_a96-36x_firmware
  • ampereone_a192-26x
  • ampereone_a144-24x
  • ampereone_a144-33m
  • ampereone_a144-27x
  • ampereone_a160-28m_firmware
  • ampereone_a192-32m
  • ampereone_a96-36x
  • ampereone_a96-36m_firmware
  • ampereone_a160-28x
  • ampereone_a192-26x_firmware
  • ampereone_a144-33m_firmware
  • ampereone_a144-26m_firmware
  • ampereone_a128-34x_firmware
  • ampereone_a160-28m
  • ampereone_a192-32x_firmware
  • ampereone_a192-26m_firmware
  • ampereone_a192-32m_firmware
CWE
CWE-787

Out-of-bounds Write