5.5

CVE-2021-46766

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

Data is provided by the National Vulnerability Database (NVD)
AmdEpyc 9654p Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9654p Version-
AmdEpyc 9654 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9654 Version-
AmdEpyc 9634 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9634 Version-
AmdEpyc 9554p Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9554p Version-
AmdEpyc 9554 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9554 Version-
AmdEpyc 9534 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9534 Version-
AmdEpyc 9474f Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9474f Version-
AmdEpyc 9454p Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9454p Version-
AmdEpyc 9454 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9454 Version-
AmdEpyc 9374f Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9374f Version-
AmdEpyc 9354p Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9354p Version-
AmdEpyc 9354 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9354 Version-
AmdEpyc 9334 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9334 Version-
AmdEpyc 9274f Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9274f Version-
AmdEpyc 9254 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9254 Version-
AmdEpyc 9224 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9224 Version-
AmdEpyc 9174f Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9174f Version-
AmdEpyc 9124 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9124 Version-
AmdEpyc 9684x Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9684x Version-
AmdEpyc 9384x Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9384x Version-
AmdEpyc 9184x Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9184x Version-
AmdEpyc 9754 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9754 Version-
AmdEpyc 9754s Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9754s Version-
AmdEpyc 9734 Firmware Version < genoapi_1.0.0.4
   AmdEpyc 9734 Version-
AmdRyzen Threadripper Pro 3995wx Firmware Version < chagallwspi-swrx8_1.0.0.5
AmdRyzen Threadripper Pro 3975wx Firmware Version < chagallwspi-swrx8_1.0.0.5
AmdRyzen Threadripper Pro 3955wx Firmware Version < chagallwspi-swrx8_1.0.0.5
AmdRyzen Threadripper Pro 3945wx Firmware Version < chagallwspi-swrx8_1.0.0.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.033
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
psirt@amd.com 2.5 0.8 1.4
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.