Vulnerability Description
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Epyc 7H12 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7H12 | - |
| Amd | Epyc 7F72 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7F72 | - |
| Amd | Epyc 7F52 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7F52 | - |
| Amd | Epyc 7F32 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7F32 | - |
| Amd | Epyc 7742 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7742 | - |
| Amd | Epyc 7702P Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7702P | - |
| Amd | Epyc 7702 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7702 | - |
| Amd | Epyc 7662 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7662 | - |
| Amd | Epyc 7642 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7642 | - |
| Amd | Epyc 7552 Firmware | < romepi_1.0.0.d |
| Amd | Epyc 7552 | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032Vendor Advisory
FAQ
What is CVE-2021-26316?
CVE-2021-26316 is a vulnerability with a CVSS score of 7.8 (HIGH). Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code ex...
How severe is CVE-2021-26316?
CVE-2021-26316 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26316?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Epyc 7H12 Firmware, Amd Epyc 7H12, Amd Epyc 7F72 Firmware, Amd Epyc 7F72, Amd Epyc 7F52 Firmware.