CVE-2021-46767Improper Input Validation in AMD Milanpi Firmware

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 71.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11

Description

Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 0.9 | Impact: 5.2

Affected Packages4 packages

NVDamd/romepi_firmware< 1.0.0.d
NVDamd/milanpi_firmware< 1.0.0.6
CVEListV5amd/2nd_gen_epycvarious
CVEListV5amd/3rd_gen_epycvarious

🔴Vulnerability Details

2
GHSA
GHSA-r95c-v4c6-2xcg: Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss2023-01-11
CVEList
CVE-2021-46767: Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss2023-01-10
CVE-2021-46767 — Improper Input Validation in AMD | cvebase