First published: Tue Jan 10 2023(Updated: )
Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amd Romepi Firmware | <1.0.0.d | |
Amd Romepi | ||
Amd Milanpi Firmware | <1.0.0.5 | |
Amd Milanpi |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-46768.
The severity of CVE-2021-46768 is medium.
The affected software for CVE-2021-46768 is Amd Romepi Firmware version up to but excluding 1.0.0.d and Amd Milanpi Firmware version up to but excluding 1.0.0.5.
CVE-2021-46768 may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
No, Amd Romepi and Amd Milanpi are not vulnerable to CVE-2021-46768.