CVE-2021-26402

Severity
7.1HIGH
EPSS
0.1%
top 83.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11

Description

Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages52 packages

NVDamd/epyc_7002_firmware< romepi_1.0.0.c
NVDamd/epyc_7003_firmware< milanpi_1.0.0.4
NVDamd/epyc_7252_firmware< romepi_1.0.0.c
NVDamd/epyc_7262_firmware< romepi_1.0.0.c
NVDamd/epyc_7272_firmware< romepi_1.0.0.c

🔴Vulnerability Details

2
GHSA
GHSA-f358-f8cc-67vr: Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-con2023-01-11
CVEList
CVE-2021-26402: Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-con2023-01-10
CVE-2021-26402 (HIGH CVSS 7.1) | Insufficient bounds checking in ASP | cvebase.io