HIGH · 7.8

CVE-2021-26316

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code ex...

Vulnerability Description

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdEpyc 7H12 Firmware< romepi_1.0.0.d
AmdEpyc 7H12-
AmdEpyc 7F72 Firmware< romepi_1.0.0.d
AmdEpyc 7F72-
AmdEpyc 7F52 Firmware< romepi_1.0.0.d
AmdEpyc 7F52-
AmdEpyc 7F32 Firmware< romepi_1.0.0.d
AmdEpyc 7F32-
AmdEpyc 7742 Firmware< romepi_1.0.0.d
AmdEpyc 7742-
AmdEpyc 7702P Firmware< romepi_1.0.0.d
AmdEpyc 7702P-
AmdEpyc 7702 Firmware< romepi_1.0.0.d
AmdEpyc 7702-
AmdEpyc 7662 Firmware< romepi_1.0.0.d
AmdEpyc 7662-
AmdEpyc 7642 Firmware< romepi_1.0.0.d
AmdEpyc 7642-
AmdEpyc 7552 Firmware< romepi_1.0.0.d
AmdEpyc 7552-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-26316?

CVE-2021-26316 is a vulnerability with a CVSS score of 7.8 (HIGH). Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code ex...

How severe is CVE-2021-26316?

CVE-2021-26316 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-26316?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Epyc 7H12 Firmware, Amd Epyc 7H12, Amd Epyc 7F72 Firmware, Amd Epyc 7F72, Amd Epyc 7F52 Firmware.