CVE Vulnerabilities

CVE-2024-56161

Improper Verification of Cryptographic Signature

Published: Feb 03, 2025 | Modified: Feb 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.2 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Ubuntu
MEDIUM

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

References