First published: Tue Feb 13 2024(Updated: )
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
AMD Ryzen Embedded 5950E Firmware | <embam4pi_1.0.0.0 | |
AMD Ryzen Embedded 5950E Firmware | ||
All of | ||
AMD Ryzen Embedded 5900E Firmware | <embam4pi_1.0.0.0 | |
AMD Ryzen Embedded 5900E | ||
All of | ||
AMD Ryzen Embedded 5800E Firmware | <embam4pi_1.0.0.0 | |
AMD Ryzen Embedded 5800E Firmware | ||
All of | ||
AMD Ryzen Embedded 5600E | <embam4pi_1.0.0.0 | |
AMD Ryzen Embedded 5600E Firmware | ||
All of | ||
AMD Ryzen Embedded V2516 | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded V2516 Firmware | ||
All of | ||
AMD Ryzen Embedded V2546 | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded V2546 Firmware | ||
All of | ||
AMD Ryzen Embedded V2718 Firmware | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded V2718 Firmware | ||
All of | ||
AMD Ryzen Embedded V2748 | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded V2748 Firmware | ||
All of | ||
AMD Ryzen Embedded R2312 Firmware | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded R2312 Firmware | ||
All of | ||
AMD Ryzen Embedded R2314 | <embeddedpi-fp6_1.0.0.6 | |
AMD Ryzen Embedded R2314 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46757 has a medium severity rating due to potential privilege escalation risks.
To fix CVE-2021-46757, update the firmware of the affected AMD Ryzen Embedded products to the latest version that addresses the vulnerability.
CVE-2021-46757 affects several AMD Ryzen Embedded firmware versions, including those for 5950E, 5900E, 5800E, and other Ryzen Embedded models.
An attacker exploiting CVE-2021-46757 could read or write to the ASP Secure OS kernel virtual address space, potentially allowing privilege escalation.
Yes, AMD has released a patch for CVE-2021-46757 in the latest firmware updates for affected products.