CVE Vulnerabilities

CVE-2021-46758

Published: Nov 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.

Affected Software

NameVendorStart VersionEnd Version
Ryzen_7_5700g_firmwareAmd*comboam4v2_pi_1.2.0.8 (excluding)

References