MEDIUM · 5.6

CVE-2021-46778

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By m...

Vulnerability Description

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

CVSS Score

5.6

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AmdAthlon 3050Ge Firmware-
AmdAthlon 3050Ge-
AmdAthlon 3150G Firmware-
AmdAthlon 3150G-
AmdAthlon 3150Ge Firmware-
AmdAthlon 3150Ge-
AmdEpyc 7001 Firmware-
AmdEpyc 7001-
AmdEpyc 7002 Firmware-
AmdEpyc 7002-
AmdEpyc 7003 Firmware-
AmdEpyc 7003-
AmdEpyc 7232P Firmware-
AmdEpyc 7232P-
AmdEpyc 7251 Firmware-
AmdEpyc 7251-
AmdEpyc 7252 Firmware-
AmdEpyc 7252-
AmdEpyc 7261 Firmware-
AmdEpyc 7261-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-46778?

CVE-2021-46778 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By m...

How severe is CVE-2021-46778?

CVE-2021-46778 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-46778?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Athlon 3050Ge Firmware, Amd Athlon 3050Ge, Amd Athlon 3150G Firmware, Amd Athlon 3150G, Amd Athlon 3150Ge Firmware.