5.5
CVE-2021-26343
- EPSS 0.04%
- Veröffentlicht 11.01.2023 08:15:10
- Zuletzt bearbeitet 09.04.2025 14:15:22
- Quelle psirt@amd.com
- Teams Watchlist Login
- Unerledigt Login
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Epyc 7003 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 72f3 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7313 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7313p Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7343 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7373x Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 73f3 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7413 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7443 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7443p Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7453 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 74f3 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7513 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7543 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7543p Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7573x Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 75f3 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7643 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7663 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7713 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7713p Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7743 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7763 Firmware Version < milanpi_1.0.0.3
Amd ≫ Epyc 7773x Firmware Version < milanpi_1.0.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.132 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.