cbcvebase.
CVE-2021-26387
published 2024-08-13

CVE-2021-26387: Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions…

PriorityP411low3.9CVSS 3.1
AVLACHPRHUINSCCNILAL
EPSS
0.15%
4.2th percentile
Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.

Affected

8 ranges
VendorProductVersion rangeFixed in
amdamd_epyc_7001_series_processors
amdamd_epyc_7002_series_processors
amdamd_epyc_7003_series_processors
amdamd_epyc_9004_series_processors
amdamd_epyc_embedded_3000_series_processors
amdamd_epyc_embedded_7002_series_processors
amdamd_epyc_embedded_7003_series_processors
amdamd_epyc_embedded_9003_series_processors
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.