ZeroHour

CVE-2021-46759

CVSS 3.1
6.1 medium
EPSS
<1%p21
Published
()
Modified
Description

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

Vendors
amd
Products
ryzen 5300g firmware, ryzen 5300ge firmware, ryzen 5500 firmware, ryzen 5600 firmware, ryzen 5600g firmware, ryzen 5600ge firmware, ryzen 5600x firmware, ryzen 5700g firmware, ryzen 5700ge firmware, ryzen 5700x firmware, ryzen 5800 firmware, ryzen 5800x3d firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.