CVE-2021-26407: Medium severity amd romepi firmware vulnerability
Published Jan 10, 2023
·Updated
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.
Affected Software
4 affected components
AMD Romepi Firmware<1.0.0.a
AMD Romepi
All of the following
AMD Romepi Firmware<1.0.0.a
AMD Romepi
Event History
Jan 10, 2023
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
Description
Frequently Asked Questions
1
What is CVE-2021-26407?
CVE-2021-26407 is a vulnerability that occurs when a randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key, potentially resulting in information disclosure.
2
What is the severity of CVE-2021-26407?
The severity of CVE-2021-26407 is medium with a severity value of 5.5.
3
Which software is affected by CVE-2021-26407?
The affected software is Amd Romepi Firmware version up to exclusive 1.0.0.a.
4
How can CVE-2021-26407 be exploited?
CVE-2021-26407 can be exploited when a collision of IVs with the same key occurs, leading to potential information disclosure.
5
How can I fix CVE-2021-26407?
To fix CVE-2021-26407, it is recommended to update to a version of Amd Romepi Firmware that is not vulnerable to this issue.