VulnerabilityModified
CVE-2021-46748
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
MEDIUM 5.5EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/radeon rx vega m firmware · amd/radeon software · amd/radeon rx vega 56 firmware · amd/radeon rx vega 64 firmware · amd/radeon pro vega 56 firmware · amd/radeon pro vega 64 firmware
- Source
- psirt@amd.com
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.htmlVendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-6003Vendor Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00971.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.