CVE-2021-26370
—CVSS 3.1
7.1 high
EPSS
<1%p13
Published
()
Modified
Description
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
- Vendors
- amd
- Products
- epyc 7763 firmware, epyc 7713p firmware, epyc 7713 firmware, epyc 7663 firmware, epyc 7643 firmware, epyc 75f3 firmware, epyc 7543p firmware, epyc 7543 firmware, epyc 7513 firmware, epyc 7453 firmware, epyc 74f3 firmware, epyc 7443p firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.