CVE-2021-26343: Medium severity amd epyc 7003 firmware vulnerability
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26343?
CVE-2021-26343 is a vulnerability that allows malicious supervisor x86 software to disclose the contents of sensitive memory, resulting in information disclosure.
Which software is affected by CVE-2021-26343?
The Amd Epyc 7003 Firmware versions up to exclusive milanpi_1.0.0.3 and Amd Epyc 72f3, 7313, 7313p, 7343, 7373x, 73f3, 7413, 7443, 7443p, 7453, 74f3, 7513, 7543, 7543p, 7573x, 75f3, 7643, 7663, 7713, 7713p, 7743, 7763, and 7773x are vulnerable to this vulnerability.
What is the severity of CVE-2021-26343?
The severity of CVE-2021-26343 is medium with a CVSS score of 5.5.
How can I fix CVE-2021-26343?
To fix CVE-2021-26343, it is recommended to apply the relevant security patches provided by AMD.
Where can I find more information about CVE-2021-26343?
You can find more information about CVE-2021-26343 on the AMD Product Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032.