ZeroHour

CVE-2021-46754

CVSS 3.1
9.1 critical
EPSS
<1%p45
Published
()
Modified
Description

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

Vendors
amd
Products
ryzen 5300g firmware, ryzen 5300ge firmware, ryzen 5500 firmware, ryzen 5600 firmware, ryzen 5600g firmware, ryzen 5600ge firmware, ryzen 5600x firmware, ryzen 5700g firmware, ryzen 5700ge firmware, ryzen 5700x firmware, ryzen 5800 firmware, ryzen 5800x3d firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.