CVE-2025-63913
7.5OpenSBI · OpenSBI
OpenSBI 1.3 is vulnerable to a denial of service attack via a crafted request to the SBI function #2 or the SBI PMU extension counter configuration function.
Executive summary
An unauthenticated remote attacker can cause a denial of service in OpenSBI 1.3 by sending a specially crafted request to specific SBI functions.
Vulnerability
This vulnerability involves a denial of service flaw triggered by crafted requests to the SBI function #2 or the Find and configure a matching counter function of the SBI PMU extension, which can be exploited by an unauthenticated attacker over the network.
Business impact
The exploitation of this vulnerability results in service disruption, preventing the affected system from performing its intended functions. Given the CVSS score of 7.5, this represents a high-severity risk that could lead to significant operational downtime for critical infrastructure components relying on OpenSBI.
Remediation
Immediate Action: Monitor official OpenSBI channels for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Review system and access logs for unusual request patterns targeting SBI function calls or PMU extension configuration parameters.
Compensating Controls: Implement network-level filtering to restrict access to the underlying management interfaces where possible to reduce the attack surface.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Organizations utilizing OpenSBI 1.3 should treat this vulnerability with high priority due to its potential for remote denial of service. Administrators must track vendor updates closely and prioritize the deployment of the forthcoming patch to ensure system availability and resilience against potential disruption.