CVE-2025-14304
Severity CVSS v4.0:
HIGH
Type:
CWE-693
Protection Mechanism Failure
Publication date:
17/12/2025
Last modified:
17/12/2025
Description
Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.80
Severity 3.x
MEDIUM



