Insufficient Validation Vulnerability in AMD Secure Processor Bootloader
CVE-2021-46758
6.1MEDIUM
Key Information:
- Vendor
- Amd
- Status
- Vendor
- CVE Published:
- 14 November 2023
Summary
The AMD Secure Processor bootloader features insufficient validation of SPI flash addresses, potentially enabling an attacker to access data in memory areas beyond the designated SPI flash. This may result in a compromise of both the availability and integrity of data, posing significant risks to the security posture of affected systems.
Affected Version(s)
AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics “Barcelo” x86 various
AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics "Rembrandt" x86 various
AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics “Barcelo-R” x86 various
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved