CVE-2021-46768: Input Validation
Published Jan 10, 2023
·Updated
Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
Affected Software
4 affected components
AMD Romepi Firmware<1.0.0.d
AMD Romepi
AMD Milanpi Firmware<1.0.0.5
AMD Milanpi
Event History
Jan 10, 2023
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-46768.
2
What is the severity of CVE-2021-46768?
The severity of CVE-2021-46768 is medium.
3
What is the affected software for CVE-2021-46768?
The affected software for CVE-2021-46768 is Amd Romepi Firmware version up to but excluding 1.0.0.d and Amd Milanpi Firmware version up to but excluding 1.0.0.5.
4
What is the potential impact of CVE-2021-46768?
CVE-2021-46768 may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
5
Is Amd Romepi and Amd Milanpi vulnerable to CVE-2021-46768?
No, Amd Romepi and Amd Milanpi are not vulnerable to CVE-2021-46768.