Insufficient Validation Vulnerability in AMD Secure Processor Bootloader
CVE-2021-46758

6.1MEDIUM

Summary

The AMD Secure Processor bootloader features insufficient validation of SPI flash addresses, potentially enabling an attacker to access data in memory areas beyond the designated SPI flash. This may result in a compromise of both the availability and integrity of data, posing significant risks to the security posture of affected systems.

Affected Version(s)

AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics “Barcelo” x86 various

AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics "Rembrandt" x86 various

AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics “Barcelo-R” x86 various

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.