CVE-2021-46758
published 2023-11-14CVE-2021-46758: Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI…
PriorityP423medium6.1CVSS 3.1
AVPACLPRNUINSUCNIHAH
EPSS
0.33%
24.7th percentile
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_ryzen_5000_series_processors_with_radeon_graphics_barcelo | — | — |
| amd | amd_ryzen_6000_series_processors_with_radeon_graphics_rembrandt | — | — |
| amd | amd_ryzen_7030_series_mobile_processors_with_radeon_graphics_barcelo-r | — | — |
| amd | amd_ryzen_7035_series_processors_with_radeon_graphics_rembrandt-r | — | — |
| amd | ryzen_3_4300u_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_3_5125c_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_3_5300g_firmware | < comboam4v2_pi_1.2.0.8 | comboam4v2_pi_1.2.0.8 |
| amd | ryzen_3_5300ge_firmware | < comboam4v2_pi_1.2.0.8 | comboam4v2_pi_1.2.0.8 |
| amd | ryzen_3_5300u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_3_5400u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_3_5425u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_3_7335u_firmware | < rembrandtpi-fp7_1.0.0.5 | rembrandtpi-fp7_1.0.0.5 |
| amd | ryzen_3_pro_7330u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_4000_series_mobile_processors_with_radeon_graphics_renoir_fp6 | — | — |
| amd | ryzen_5000_series_desktop_processor_with_radeon_graphics_cezanne | — | — |
| amd | ryzen_5000_series_mobile_processors_with_radeon_graphics_cezanne | — | — |
| amd | ryzen_5000_series_mobile_processors_with_radeon_graphics_lucienne | — | — |
| amd | ryzen_5_4500u_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_5_4600h_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_5_4600hs_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_5_4600u_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_5_4680u_firmware | < renoirpi-fp6_1.0.0.a | renoirpi-fp6_1.0.0.a |
| amd | ryzen_5_5500h_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_5_5500u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
| amd | ryzen_5_5560u_firmware | < cezannepi-fp6_1.0.0.c | cezannepi-fp6_1.0.0.c |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-11-14
Published