CVE-2021-46766: Medium severity amd epyc 9654p firmware vulnerability
Published Nov 14, 2023
·Updated
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
Affected Software
56 affected components
All of the following
AMD Epyc 9654p Firmware<genoapi_1.0.0.4
AMD Epyc 9654p
All of the following
AMD Epyc 9654 Firmware<genoapi_1.0.0.4
AMD Epyc 9654
All of the following
AMD Epyc 9634 Firmware<genoapi_1.0.0.4
AMD Epyc 9634
All of the following
AMD Epyc 9554p Firmware<genoapi_1.0.0.4
AMD Epyc 9554p
All of the following
AMD Epyc 9554 Firmware<genoapi_1.0.0.4
AMD Epyc 9554
All of the following
AMD Epyc 9534 Firmware<genoapi_1.0.0.4
AMD Epyc 9534
All of the following
AMD Epyc 9474f Firmware<genoapi_1.0.0.4
AMD Epyc 9474f
All of the following
AMD Epyc 9454p Firmware<genoapi_1.0.0.4
AMD Epyc 9454p
All of the following
AMD Epyc 9454 Firmware<genoapi_1.0.0.4
AMD Epyc 9454
All of the following
AMD Epyc 9374f Firmware<genoapi_1.0.0.4
AMD Epyc 9374f
All of the following
AMD Epyc 9354p Firmware<genoapi_1.0.0.4
AMD Epyc 9354p
All of the following
AMD Epyc 9354 Firmware<genoapi_1.0.0.4
AMD Epyc 9354
All of the following
AMD Epyc 9334 Firmware<genoapi_1.0.0.4
AMD Epyc 9334
All of the following
AMD Epyc 9274f Firmware<genoapi_1.0.0.4
AMD Epyc 9274f
All of the following
AMD Epyc 9254 Firmware<genoapi_1.0.0.4
AMD Epyc 9254
All of the following
AMD Epyc 9224 Firmware<genoapi_1.0.0.4
AMD Epyc 9224
All of the following
AMD Epyc 9174f Firmware<genoapi_1.0.0.4
AMD Epyc 9174f
All of the following
AMD Epyc 9124 Firmware<genoapi_1.0.0.4
AMD Epyc 9124
All of the following
AMD Epyc 9684x Firmware<genoapi_1.0.0.4
AMD Epyc 9684x
All of the following
AMD Epyc 9384x Firmware<genoapi_1.0.0.4
AMD Epyc 9384x
All of the following
AMD Epyc 9184x Firmware<genoapi_1.0.0.4
AMD Epyc 9184x
All of the following
AMD Epyc 9754 Firmware<genoapi_1.0.0.4
AMD Epyc 9754
All of the following
AMD Epyc 9754s Firmware<genoapi_1.0.0.4
AMD Epyc 9754s
All of the following
AMD Epyc 9734 Firmware<genoapi_1.0.0.4
AMD Epyc 9734
All of the following
AMD Ryzen Threadripper Pro 3995wx Firmware<chagallwspi-swrx8_1.0.0.5
AMD Ryzen Threadripper Pro 3995wx
All of the following
AMD Ryzen Threadripper Pro 3975wx Firmware<chagallwspi-swrx8_1.0.0.5
AMD Ryzen Threadripper Pro 3975wx
All of the following
AMD Ryzen Threadripper Pro 3955wx Firmware<chagallwspi-swrx8_1.0.0.5
AMD Ryzen Threadripper Pro 3955wx
All of the following
AMD Ryzen Threadripper Pro 3945wx Firmware<chagallwspi-swrx8_1.0.0.5
AMD Ryzen Threadripper Pro 3945wx
Event History
Nov 14, 2023
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2021-46766?
The severity of CVE-2021-46766 is considered high due to potential exposure of sensitive data.
2
How do I fix CVE-2021-46766?
To fix CVE-2021-46766, users should update the firmware to the latest version provided by AMD.
3
What types of systems are affected by CVE-2021-46766?
CVE-2021-46766 affects several AMD EPYC and Ryzen Threadripper Pro firmware versions.
4
What could happen if CVE-2021-46766 is exploited?
Exploitation of CVE-2021-46766 could result in a loss of confidentiality by exposing secret keys to attackers.
5
Is there a workaround for CVE-2021-46766?
Currently, the recommended approach for CVE-2021-46766 is to apply the firmware update, as no specific workaround is documented.