PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-63913 OpenSBI CVE debrief

CVE-2025-63913 is a high-severity vulnerability in OpenSBI 1.3, allowing attackers to cause a denial of service via crafted requests to SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. Defenders should assess potential exposure and impact, especially for systems with internet-exposed interfaces. The vulnerability's impact on system availability and reliability requires attention. Limited information is available from the CVE record and NVD entry, with a CVSS score of 7.5 and HIGH severity. Further verification is needed to determine affected scope and vendor guidance.

Vendor
OpenSBI
Product
OpenSBI 1.3
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-09-09
Advisory published
2026-07-27
Advisory updated
2026-09-09

Who should care

Defenders responsible for systems using OpenSBI 1.3, especially those with internet-exposed interfaces, should assess potential exposure and impact.

Why it matters

CVE-2025-63913 is a high-severity vulnerability in OpenSBI 1.3 that allows attackers to cause a denial of service. Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces. The vulnerability's impact on system availability and reliability requires attention from defenders.

  • Potential denial of service on affected systems
  • Need to verify OpenSBI version and system configurations
  • Possible impact on system availability and reliability

Technical summary

The vulnerability exists in OpenSBI 1.3, allowing attackers to cause a denial of service via crafted requests to SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension. The vulnerability has a CVSS score of 7.5 and a HIGH severity rating. Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces. Limited information is available from the CVE record and NVD entry.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on systems using OpenSBI 1.3, especially those with internet-exposed interfaces.

Recommended defensive actions

  • Verify OpenSBI version and assess exposure
  • Review system configurations and internet exposure
  • Monitor for potential denial of service attempts

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 7.5 and a HIGH severity rating. Evidence is limited to source-provided CVE metadata and NIST NVD detail page assessments. Defenders should verify OpenSBI version and system configurations, review system exposure, and monitor for potential denial of service attempts. The vulnerability's impact on system availability and reliability requires attention from defenders. No additional facts

Sources and references

Verified primary and authoritative sources

  • CVE-2025-63913 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-63913

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-63913 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-63913

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.