CVE-2021-26402
—CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
Description
Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.
- Vendors
- amd
- Products
- epyc 7h12 firmware, epyc 7f72 firmware, epyc 7f52 firmware, epyc 7f32 firmware, epyc 7742 firmware, epyc 7702p firmware, epyc 7702 firmware, epyc 7662 firmware, epyc 7642 firmware, epyc 7552 firmware, epyc 7542 firmware, epyc 7532 firmware
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.