SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26346

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

MEDIUM 5.5EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.21% probability · 12th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
amd/ryzen 3 3100 firmware · amd/ryzen 3 3200g firmware · amd/ryzen 3 3200u firmware · amd/ryzen 3 3250c firmware · amd/ryzen 3 3250u firmware · amd/ryzen 3 3300g firmware · amd/ryzen 3 3300u firmware · amd/ryzen 3 3300x firmware · amd/ryzen 3 3350u firmware · amd/ryzen 3 3450u firmware · amd/ryzen 3 3500c firmware · amd/ryzen 3 3500u firmware · amd/ryzen 3 3550h firmware · amd/ryzen 3 3580u firmware · amd/ryzen 3 3700c firmware · amd/ryzen 3 3700u firmware · amd/ryzen 3 3750h firmware · amd/ryzen 3 3780u firmware · amd/ryzen 3 5125c firmware · amd/ryzen 3 5300g firmware · +40 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.