ZeroHour

CVE-2021-26346

CVSS 3.1
5.5 medium
EPSS
<1%p11
Published
()
Modified
Description

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

Vendors
amd
Products
ryzen 3 3100 firmware, ryzen 3 3200g firmware, ryzen 3 3200u firmware, ryzen 3 3250c firmware, ryzen 3 3250u firmware, ryzen 3 3300g firmware, ryzen 3 3300u firmware, ryzen 3 3300x firmware, ryzen 3 3350u firmware, ryzen 3 3450u firmware, ryzen 3 3500c firmware, ryzen 3 3500u firmware
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.