CVE-2021-26371
—CVSS 3.1
5.5 medium
EPSS
<1%p9
Published
()
Modified
Description
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
- Vendors
- amd
- Products
- epyc 7773x firmware, epyc 7763 firmware, epyc 7713p firmware, epyc 7713 firmware, epyc 7663 firmware, epyc 7643 firmware, epyc 75f3 firmware, epyc 7573x firmware, epyc 7543p firmware, epyc 7543 firmware, epyc 7513 firmware, epyc 74f3 firmware
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.