CRITICAL · 9.1

CVE-2021-46753

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwri...

Vulnerability Description

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AmdRyzen 6600H Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6600H-
AmdRyzen 6600Hs Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6600Hs-
AmdRyzen 6600U Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6600U-
AmdRyzen 6800H Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6800H-
AmdRyzen 6800Hs Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6800Hs-
AmdRyzen 6800U Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6800U-
AmdRyzen 6900Hs Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6900Hs-
AmdRyzen 6900Hx Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6900Hx-
AmdRyzen 6980Hs Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6980Hs-
AmdRyzen 6980Hx Firmwarerembrandtpi-fp7_1.0.0.5
AmdRyzen 6980Hx-

References

FAQ

What is CVE-2021-46753?

CVE-2021-46753 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwri...

How severe is CVE-2021-46753?

CVE-2021-46753 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-46753?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 6600H Firmware, Amd Ryzen 6600H, Amd Ryzen 6600Hs Firmware, Amd Ryzen 6600Hs, Amd Ryzen 6600U Firmware.