Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2021-26315

When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

  • Published: Nov 16, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-26315
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Low
  • Score: 4.6
  • AV:L/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
amd / epyc_7003_firmware - milanpi-sp3_1.0.0.4
amd / epyc_72f3_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7313_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7313p_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7343_firmware - milanpi-sp3_1.0.0.4
amd / epyc_73f3_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7413_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7443_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7443p_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7453_firmware - milanpi-sp3_1.0.0.4
amd / epyc_74f3_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7513_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7543_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7543p_firmware - milanpi-sp3_1.0.0.4
amd / epyc_75f3_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7643_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7663_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7713_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7713p_firmware - milanpi-sp3_1.0.0.4
amd / epyc_7763_firmware - milanpi-sp3_1.0.0.4