ZeroHour

CVE-2021-26347

CVSS 3.1
4.7 medium
EPSS
<1%p9
Published
()
Modified
Description

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

Vendors
amd
Products
epyc 7763 firmware, epyc 7713p firmware, epyc 7713 firmware, epyc 7663 firmware, epyc 7643 firmware, epyc 75f3 firmware, epyc 7543p firmware, epyc 7543 firmware, epyc 7513 firmware, epyc 7453 firmware, epyc 74f3 firmware, epyc 7443p firmware
Weakness
CWE-1284
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.