CVE-2021-46771 — Improper Input Validation in AMD Epyc 72f3 Firmware
Severity
7.8HIGHNVD
EPSS
0.1%
top 71.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Latest updateMay 11
Description
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages24 packages
🔴Vulnerability Details
2GHSA▶
GHSA-qfcc-w88q-7m85: Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromi↗2022-05-11
CVEList▶
CVE-2021-46771: Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromi↗2022-05-10