CVE Vulnerabilities

CVE-2021-46766

Incomplete Cleanup

Published: Nov 14, 2023 | Modified: Feb 13, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Epyc_9654p_firmware Amd * genoapi_1.0.0.4 (excluding)

Potential Mitigations

References