CVE-2026-40677 PUBLISHED

Assigner: AMD
Reserved: 14.04.2026 Published: 12.06.2026 Updated: 12.06.2026

The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor AMD
Product AMD Management Console (AMC)
Versions Default: affected
  • Version 14.0.0 is unaffected
Vendor AMD
Product AMD Ryzen™ Master
Versions Default: affected
  • Version 2.14.3 is unaffected
Vendor AMD
Product AMD µProf
Versions Default: affected
  • Version 5.3 is unaffected

References

Problem Types

  • CWE-1428 Reliance on HTTP instead of HTTPS CWE