HIGH · 7.5

CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a...

Vulnerability Description

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
AmdRyzen 5300G Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5300G-
AmdRyzen 5300Ge Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5300Ge-
AmdRyzen 5500 Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5500-
AmdRyzen 5600 Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5600-
AmdRyzen 5600G Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5600G-
AmdRyzen 5600Ge Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5600Ge-
AmdRyzen 5600X Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5600X-
AmdRyzen 5700G Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5700G-
AmdRyzen 5700Ge Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5700Ge-
AmdRyzen 5700X Firmwarecezannepi-fp6_1.0.0.6
AmdRyzen 5700X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-46794?

CVE-2021-46794 is a vulnerability with a CVSS score of 7.5 (HIGH). Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a...

How severe is CVE-2021-46794?

CVE-2021-46794 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-46794?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 5300G Firmware, Amd Ryzen 5300G, Amd Ryzen 5300Ge Firmware, Amd Ryzen 5300Ge, Amd Ryzen 5500 Firmware.