VulnerabilityModified
CVE-2021-26333
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver.
MEDIUM 5.5EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-909
- Affected
- amd/chipset driver · amd/psp driver
- Source
- psirt@amd.com
References
- http://packetstormsecurity.com/files/164202/AMD-Chipset-Driver-Information-Disclosure-Memory-Leak.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Sep/24Mailing List, Third Party Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1009Vendor Advisory
- http://packetstormsecurity.com/files/164202/AMD-Chipset-Driver-Information-Disclosure-Memory-Leak.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2021/Sep/24Mailing List, Third Party Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1009Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.