cbcvebase.
CVE-2021-46795
published 2023-01-11

CVE-2021-46795: A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.14%
3.5th percentile
A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.

Affected

5 ranges
VendorProductVersion rangeFixed in
amdcezannepi-fp6_firmware< 1.0.0.61.0.0.6
amdcomboam4v2_pi_firmware< 1.2.0.51.2.0.5
amdrenoirpi-fp6_firmware< 1.0.0.71.0.0.7
amdryzen_3000_series
amdryzen_5000_series

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.