CVE-2021-26315: High severity amd epyc 7003 firmware vulnerability
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26315?
CVE-2021-26315 is a vulnerability in the AMD Platform Security Processor (PSP) boot rom that allows arbitrary code execution when encrypted firmware images are used.
What software versions are affected by CVE-2021-26315?
The affected software versions are AMD Epyc 7003 Firmware (up to exclusive version milanpi-sp3_1.0.0.4) and AMD Epyc 72f3, 7313, 7313p, 7343, 73f3, 7413, 7443, 7443p, 7453, 74f3, 7513, 7543, 7543p, 75f3, 7643, 7663, 7713, 7713p, and 7763 Firmware (up to exclusive version milanpi-sp3_1.0.0.4).
What is the severity of CVE-2021-26315?
The severity of CVE-2021-26315 is high with a CVSS score of 7.8.
How can I fix CVE-2021-26315?
To fix CVE-2021-26315, it is recommended to update to the latest firmware version provided by AMD.
Where can I find more information about CVE-2021-26315?
You can find more information about CVE-2021-26315 on the AMD Product Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1021.