SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26355

Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

MEDIUM 5.5EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-693
Affected
amd/epyc 7003 firmware · amd/epyc 72f3 firmware · amd/epyc 7313 firmware · amd/epyc 7313p firmware · amd/epyc 7343 firmware · amd/epyc 7373x firmware · amd/epyc 73f3 firmware · amd/epyc 7413 firmware · amd/epyc 7443 firmware · amd/epyc 7443p firmware · amd/epyc 7453 firmware · amd/epyc 74f3 firmware · amd/epyc 7513 firmware · amd/epyc 7543 firmware · amd/epyc 7543p firmware · amd/epyc 7573x firmware · amd/epyc 75f3 firmware · amd/epyc 7643 firmware · amd/epyc 7663 firmware · amd/epyc 7713 firmware · +4 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.