7.8
CVE-2021-26315
- EPSS 0.03%
- Published 16.11.2021 19:15:07
- Last modified 21.11.2024 05:56:04
- Source psirt@amd.com
- Teams watchlist Login
- Open Login
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.
Data is provided by the National Vulnerability Database (NVD)
Amd ≫ Epyc 7003 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 72f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7313 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7313p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7343 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 73f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7413 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7443 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7443p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7453 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 74f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7513 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7543 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7543p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 75f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7643 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7663 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7713 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7713p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7763 Firmware Version < milanpi-sp3_1.0.0.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.057 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.