ZeroHour

CVE-2021-46758

CVSS 3.1
6.1 medium
EPSS
<1%p25
Published
()
Modified
Description

Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.

Vendors
amd
Products
ryzen 7 5700g firmware, ryzen 7 5700ge firmware, ryzen 5 5600g firmware, ryzen 5 5600ge firmware, ryzen 3 5300g firmware, ryzen 3 5300ge firmware, ryzen 9 7950x3d firmware, ryzen 9 7900x3d firmware, ryzen 7 7800x3d firmware, ryzen 9 4900h firmware, ryzen 9 4900hs firmware, ryzen 7 4800h firmware
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.