CVE-2021-46756

Severity
9.1CRITICAL
EPSS
0.2%
top 63.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9

Description

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2

🔴Vulnerability Details

2
GHSA
GHSA-p57x-q6x3-v235: Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or AB2023-05-09
CVEList
CVE-2021-46756: Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or AB2023-05-09
CVE-2021-46756 (CRITICAL CVSS 9.1) | Insufficient validation of inputs i | cvebase.io