7.1
CVE-2021-46779
- EPSS 0.04%
- Published 11.01.2023 08:15:13
- Last modified 09.04.2025 15:15:44
- Source psirt@amd.com
- Teams watchlist Login
- Open Login
Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
Data is provided by the National Vulnerability Database (NVD)
Amd ≫ Romepi Firmware Version < 1.0.0.c
Amd ≫ Milanpi Firmware Version < 1.0.0.4
Amd ≫ Naplespi Firmware Version < 1.0.0.g
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.125 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.