SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-46748

Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.

MEDIUM 5.5EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.21% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
intel/radeon rx vega m firmware · amd/radeon software · amd/radeon rx vega 56 firmware · amd/radeon rx vega 64 firmware · amd/radeon pro vega 56 firmware · amd/radeon pro vega 64 firmware
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.