CVE-2020-12946: Input Validation
Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12946?
CVE-2020-12946 has been classified as a high severity vulnerability due to potential loss of integrity and denial of service.
How do I fix CVE-2020-12946?
To fix CVE-2020-12946, update to the latest firmware version provided by AMD for your specific EPYC processor.
What products are affected by CVE-2020-12946?
CVE-2020-12946 affects various AMD EPYC processor firmware versions prior to 'romepi-sp3_1.0.0.c' or 'milanpi-sp3_1.0.0.4' depending on the CPU model.
What does insufficient input validation mean in CVE-2020-12946?
Insufficient input validation in CVE-2020-12946 indicates that the firmware does not adequately check the inputs to discrete TPM (Trusted Platform Module) commands, which can lead to security vulnerabilities.
Can CVE-2020-12946 be exploited remotely?
Yes, CVE-2020-12946 can potentially be exploited remotely, allowing attackers to affect system integrity and availability.