Aller au contenu

Fiche vulnérabilité

CVE-2021-26315 : faille élevée AMD 3rd Gen AMD EPYC™ (CVSS 7.8)

Description

When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 nov. 2021
Dernière mise à jour
17 sept. 2024

Produits concernés

  • AMD 3rd Gen AMD EPYC™

Références

Rechercher une autre vulnérabilité dans la base CVE