5.5

CVE-2021-26343

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.


Data is provided by the National Vulnerability Database (NVD)
AmdEpyc 7003 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7003 Version-
AmdEpyc 72f3 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 72f3 Version-
AmdEpyc 7313 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7313 Version-
AmdEpyc 7313p Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7313p Version-
AmdEpyc 7343 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7343 Version-
AmdEpyc 7373x Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7373x Version-
AmdEpyc 73f3 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 73f3 Version-
AmdEpyc 7413 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7413 Version-
AmdEpyc 7443 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7443 Version-
AmdEpyc 7443p Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7443p Version-
AmdEpyc 7453 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7453 Version-
AmdEpyc 74f3 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 74f3 Version-
AmdEpyc 7513 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7513 Version-
AmdEpyc 7543 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7543 Version-
AmdEpyc 7543p Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7543p Version-
AmdEpyc 7573x Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7573x Version-
AmdEpyc 75f3 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 75f3 Version-
AmdEpyc 7643 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7643 Version-
AmdEpyc 7663 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7663 Version-
AmdEpyc 7713 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7713 Version-
AmdEpyc 7713p Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7713p Version-
AmdEpyc 7743 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7743 Version-
AmdEpyc 7763 Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7763 Version-
AmdEpyc 7773x Firmware Version < milanpi_1.0.0.3
   AmdEpyc 7773x Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.132
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.