CVE-2021-46757
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Insufficient checking of memory buffer in ASP
Secure OS may allow an attacker with a malicious TA to read/write to the ASP
Secure OS kernel virtual address space potentially leading to privilege
escalation.
Affected (10)
Products: Amd: Ryzen Embedded 5950e Firmware, Ryzen Embedded 5900e Firmware, Ryzen Embedded 5800e Firmware, Ryzen Embedded 5600e Firmware, Ryzen Embedded V2516 Firmware, Ryzen Embedded V2546 Firmware, Ryzen Embedded V2718 Firmware, Ryzen Embedded V2748 Firmware, Ryzen Embedded R2312 Firmware, Ryzen Embedded R2314 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before embam4pi_1.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded 5950e | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before embam4pi_1.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded 5900e | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before embam4pi_1.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded 5800e | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before embam4pi_1.0.0.0 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded 5600e | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded V2516 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded V2546 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded V2718 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded V2748 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded R2312 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before embeddedpi-fp6_1.0.0.6 |
| Running on/with | Platform Versions |
|---|---|
Amd Ryzen Embedded R2314 | All versions |
References (2)
Source: psirt@amd.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.