5.5
CVE-2021-26333
- EPSS 0.12%
- Veröffentlicht 21.09.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:56:07
- Quelle psirt@amd.com
- CVE-Watchlists
- Unerledigt
AMD Chipset Driver Information Disclosure Vulnerability
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Chipset Driver Version < 3.08.17.735
Amd ≫ Psp Driver Version < 5.17.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.302 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:C/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-909 Missing Initialization of Resource
The product does not initialize a critical resource.