PatchSiren cyber security CVE debrief
CVE-2025-63913 OpenSBI CVE debrief
CVE-2025-63913 is a high-severity vulnerability in OpenSBI 1.3, allowing attackers to cause a denial of service via crafted requests to SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. Defenders should assess potential exposure and impact, especially for systems with internet-exposed interfaces. The vulnerability's impact on system availability and reliability requires attention. Limited information is available from the CVE record and NVD entry, with a CVSS score of 7.5 and HIGH severity. Further verification is needed to determine affected scope and vendor guidance.
- Vendor
- OpenSBI
- Product
- OpenSBI 1.3
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for systems using OpenSBI 1.3, especially those with internet-exposed interfaces, should assess potential exposure and impact.
Why it matters
CVE-2025-63913 is a high-severity vulnerability in OpenSBI 1.3 that allows attackers to cause a denial of service. Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces. The vulnerability's impact on system availability and reliability requires attention from defenders.
- Potential denial of service on affected systems
- Need to verify OpenSBI version and system configurations
- Possible impact on system availability and reliability
Technical summary
The vulnerability exists in OpenSBI 1.3, allowing attackers to cause a denial of service via crafted requests to SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. The vulnerability has a CVSS score of 7.5 and a HIGH severity rating. Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces. Limited information is available from the CVE record and NVD entry.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces.
Recommended defensive actions
- Verify OpenSBI version and assess exposure
- Review system configurations and internet exposure
- Monitor for potential denial of service attempts
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 7.5 and a HIGH severity rating. Evidence is limited to source-provided CVE metadata and NIST NVD detail page assessments. Defenders should verify OpenSBI version and system configurations, review system exposure, and monitor for potential denial of service attempts. The vulnerability's impact on system availability and reliability requires attention from defenders. No additional facts
Sources and references
Verified primary and authoritative sources
-
CVE-2025-63913 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-63913
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-63913 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-63913
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/luojia65/opensbi-pmu2-crash
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.