CVE-2025-22830 PUBLISHED

SmiFlash Race Condition Vulnerability

Assigner: AMI
Reserved: 08.01.2025 Published: 12.08.2025 Updated: 12.08.2025

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful exploitation of this vulnerability may lead to resource exhaustion and impact Confidentiality, Integrity, and Availability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 7.3

Product Status

Vendor AMI
Product AptioV
Versions Default: unaffected
  • affected from AptioV_5.0 to AptioV_5.040 (incl.)

References

Problem Types

  • CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE