Security Advisory

CVE-2025-14302

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-17 03:07:21
Last updated 2025-12-17 18:49:12
Assigner twcert
CVSS score 7.0
State PUBLISHED

Description

Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.