Vulnerability Description
A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Comboam4V2 Pi Firmware | < 1.2.0.5 |
| Amd | Comboam4V2 Pi | - |
| Amd | Renoirpi-Fp6 Firmware | < 1.0.0.7 |
| Amd | Cezannepi-Fp6 Firmware | < 1.0.0.6 |
| Amd | Cezannepi-Fp6 | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1031Vendor Advisory
FAQ
What is CVE-2021-46795?
CVE-2021-46795 is a vulnerability with a CVSS score of 4.7 (MEDIUM). A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of ...
How severe is CVE-2021-46795?
CVE-2021-46795 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46795?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Comboam4V2 Pi Firmware, Amd Comboam4V2 Pi, Amd Renoirpi-Fp6 Firmware, Amd Cezannepi-Fp6 Firmware, Amd Cezannepi-Fp6.