SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26393

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker…

MEDIUM 5.5EPSS 0.26%

Does this matter?

Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.26% probability · 17th percentile
CISA KEV
Not listed
Weakness
CWE-401
Affected
amd/enterprise driver · amd/radeon pro software · amd/radeon software · amd/radeon rx vega 56 firmware · amd/radeon rx vega 64 firmware · amd/ryzen 3 2200ge firmware · amd/ryzen 3 2200g firmware · amd/ryzen 5 2400ge firmware · amd/ryzen 5 2400g firmware · amd/ryzen 3 5300ge firmware · amd/ryzen 3 5300g firmware · amd/ryzen 5 5600ge firmware · amd/ryzen 5 5600g firmware · amd/ryzen 7 5700ge firmware · amd/ryzen 7 5700g firmware · amd/athlon silver 3050e firmware · amd/athlon pro 3045b firmware · amd/athlon silver 3050u firmware · amd/athlon silver 3050c firmware · amd/athlon pro 3145b firmware · +40 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.