Vulnerability Description
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 3 3100 Firmware | - |
| Amd | Ryzen 3 3100 | - |
| Amd | Ryzen 3 3200G Firmware | - |
| Amd | Ryzen 3 3200G | - |
| Amd | Ryzen 3 3200U Firmware | - |
| Amd | Ryzen 3 3200U | - |
| Amd | Ryzen 3 3250C Firmware | - |
| Amd | Ryzen 3 3250C | - |
| Amd | Ryzen 3 3250U Firmware | - |
| Amd | Ryzen 3 3250U | - |
| Amd | Ryzen 3 3300G Firmware | - |
| Amd | Ryzen 3 3300G | - |
| Amd | Ryzen 3 3300U Firmware | - |
| Amd | Ryzen 3 3300U | - |
| Amd | Ryzen 3 3300X Firmware | - |
| Amd | Ryzen 3 3300X | - |
| Amd | Ryzen 3 3350U Firmware | - |
| Amd | Ryzen 3 3350U | - |
| Amd | Ryzen 3 3450U Firmware | - |
| Amd | Ryzen 3 3450U | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
FAQ
What is CVE-2021-26346?
CVE-2021-26346 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential ...
How severe is CVE-2021-26346?
CVE-2021-26346 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26346?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 3 3100 Firmware, Amd Ryzen 3 3100, Amd Ryzen 3 3200G Firmware, Amd Ryzen 3 3200G, Amd Ryzen 3 3200U Firmware.