CRITICAL🇵🇱 Wersja polska

CVE-2026-0481

CVSS 9.2v4.0pub. 2026-05-15

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

🤖 AI Analysis
How it works

The AMD Device Metrics Exporter component does not impose appropriate restrictions on IP address binding (CWE-1327 — Binding to an Unrestricted IP Address), which means the service listens on network interfaces in an uncontrolled manner. A remote attacker, without the need for authentication and without user interaction, can send requests to this service and make unauthorized changes to GPU configuration. The attack vector is network-based, and attack complexity is low, which significantly lowers the entry threshold for a potential attacker.

Impact

An attacker can make unauthorized changes to GPU configuration, which may result in loss of device availability and related systems (SA:H). Data integrity and confidentiality are not directly threatened according to available information.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references — AMD security bulletin: https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6031.html. It is also recommended to restrict network access to the AMD Device Metrics Exporter service using a firewall or ACL rules to trusted IP addresses until the patch is deployed.

Who is affected

AMD Device Metrics Exporter included in the ROCm ecosystem; specific versions indicated in manufacturer references (AMD-SB-6031 bulletin)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References