HIGH · 7.8

CVE-2021-46757

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escal...

Vulnerability Description

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdRyzen Embedded 5950E Firmware< embam4pi_1.0.0.0
AmdRyzen Embedded 5950E-
AmdRyzen Embedded 5900E Firmware< embam4pi_1.0.0.0
AmdRyzen Embedded 5900E-
AmdRyzen Embedded 5800E Firmware< embam4pi_1.0.0.0
AmdRyzen Embedded 5800E-
AmdRyzen Embedded 5600E Firmware< embam4pi_1.0.0.0
AmdRyzen Embedded 5600E-
AmdRyzen Embedded V2516 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded V2516-
AmdRyzen Embedded V2546 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded V2546-
AmdRyzen Embedded V2718 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded V2718-
AmdRyzen Embedded V2748 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded V2748-
AmdRyzen Embedded R2312 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded R2312-
AmdRyzen Embedded R2314 Firmware< embeddedpi-fp6_1.0.0.6
AmdRyzen Embedded R2314-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-46757?

CVE-2021-46757 is a vulnerability with a CVSS score of 7.8 (HIGH). Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escal...

How severe is CVE-2021-46757?

CVE-2021-46757 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-46757?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen Embedded 5950E Firmware, Amd Ryzen Embedded 5950E, Amd Ryzen Embedded 5900E Firmware, Amd Ryzen Embedded 5900E, Amd Ryzen Embedded 5800E Firmware.