CVE-2021-46771Improper Input Validation in AMD Epyc 72f3 Firmware

Severity
7.8HIGHNVD
EPSS
0.1%
top 71.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10
Latest updateMay 11

Description

Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages24 packages

NVDamd/epyc_72f3_firmware< milanpi-sp3_1.0.0.4
NVDamd/epyc_7313_firmware< milanpi-sp3_1.0.0.4
NVDamd/epyc_7343_firmware< milanpi-sp3_1.0.0.4
NVDamd/epyc_73f3_firmware< milanpi-sp3_1.0.0.4
NVDamd/epyc_7413_firmware< milanpi-sp3_1.0.0.4

🔴Vulnerability Details

2
GHSA
GHSA-qfcc-w88q-7m85: Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromi2022-05-11
CVEList
CVE-2021-46771: Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromi2022-05-10
CVE-2021-46771 — Improper Input Validation in AMD | cvebase