CVE-2018-8933: Critical severity AMD Epyc Server Firmware vulnerability
Published Mar 22, 2018
·Updated
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
Affected Software
4 affected components
AMD Epyc Server Firmware
AMD EPYC Server
All of the following
AMD Epyc Server Firmware
AMD EPYC Server
Event History
Mar 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8933?
CVE-2018-8933 has been classified as a high severity vulnerability due to the risk it poses to the security of protected memory regions in AMD EPYC Server processors.
2
How do I fix CVE-2018-8933?
To mitigate CVE-2018-8933, ensure that you update to the latest firmware provided by AMD for its EPYC Server processors.
3
What systems are affected by CVE-2018-8933?
CVE-2018-8933 affects AMD EPYC Server processors and their associated firmware.
4
Is CVE-2018-8933 exploitable remotely?
CVE-2018-8933 can potentially be exploited locally, giving attackers access to sensitive data in protected memory.
5
When was CVE-2018-8933 disclosed?
CVE-2018-8933 was disclosed in March 2018 as part of a set of vulnerabilities affecting AMD processors.