CVE-2021-26346
—CVSS 3.1
5.5 medium
EPSS
<1%p11
Published
()
Modified
Description
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
- Vendors
- amd
- Products
- ryzen 3 3100 firmware, ryzen 3 3200g firmware, ryzen 3 3200u firmware, ryzen 3 3250c firmware, ryzen 3 3250u firmware, ryzen 3 3300g firmware, ryzen 3 3300u firmware, ryzen 3 3300x firmware, ryzen 3 3350u firmware, ryzen 3 3450u firmware, ryzen 3 3500c firmware, ryzen 3 3500u firmware
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.