7.1
CVE-2021-26370
- EPSS 0.13%
- Published 10.05.2022 19:15:08
- Last modified 21.11.2024 05:56:13
- Source psirt@amd.com
- Teams watchlist Login
- Open Login
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Data is provided by the National Vulnerability Database (NVD)
Amd ≫ Epyc 7763 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7713p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7713 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7663 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7643 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 75f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7543p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7543 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7513 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7453 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 74f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7443p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7443 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7413 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 73f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7343 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7313p Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7313 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 72f3 Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7773x Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7473x Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7573x Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7373x Firmware Version < milanpi-sp3_1.0.0.4
Amd ≫ Epyc 7002 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7232p Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7252 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7262 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7272 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7282 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7302 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7302p Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7352 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7402 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7402p Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7452 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7502 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7502p Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7532 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7542 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7552 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7642 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7662 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7702 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7702p Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7742 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7f72 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7f52 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7f32 Firmware Version < romepi-sp3_1.0.0.c
Amd ≫ Epyc 7h12 Firmware Version < romepi-sp3_1.0.0.c
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.13% | 0.326 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
nvd@nist.gov | 6.6 | 3.9 | 9.2 |
AV:L/AC:L/Au:N/C:N/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.