CVE-2021-26347
published 2022-05-11CVE-2021-26347: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory…
PriorityP417medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | epyc_7002_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7232p_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7252_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7262_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7272_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7282_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_72f3_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7302_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7302p_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7313_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7313p_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7343_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7352_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7373x_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_73f3_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7402_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7402p_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7413_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7443_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7443p_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7452_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
| amd | epyc_7453_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7473x_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_74f3_firmware | < milanpi-sp3_1.0.0.7 | milanpi-sp3_1.0.0.7 |
| amd | epyc_7502_firmware | < romepi-sp3_1.0.0.d | romepi-sp3_1.0.0.d |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Adobe Coldfusion - Authentication Bypass
nuclei·CVSS 7.5
CVE-2023-26347 [HIGH] Adobe Coldfusion - Authentication Bypass
Adobe Coldfusion - Authentication Bypass
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Template:
id: CVE-2023-26347
info:
name: Adobe Coldfusion - Authentication Bypass
author: salts
severity: high
description: |
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM an
2022-05-11
Published