CVE-2021-26343

MEDIUM

AMD EPYC 7003 Firmware < milanpi_1.0.0.3 - Information Disclosure via ASP BIOS and DRTM Commands

Title source: llm
STIX 2.1

Description

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

References (1)

Core 1
Core References

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (24)
amd/epyc_7003_firmware < milanpi_1.0.0.3
amd/epyc_72f3_firmware < milanpi_1.0.0.3
amd/epyc_7313_firmware < milanpi_1.0.0.3
amd/epyc_7313p_firmware < milanpi_1.0.0.3
amd/epyc_7343_firmware < milanpi_1.0.0.3
amd/epyc_7373x_firmware < milanpi_1.0.0.3
amd/epyc_73f3_firmware < milanpi_1.0.0.3
amd/epyc_7413_firmware < milanpi_1.0.0.3
amd/epyc_7443_firmware < milanpi_1.0.0.3
amd/epyc_7443p_firmware < milanpi_1.0.0.3
... and 14 more
Published Jan 11, 2023
Tracked Since Feb 18, 2026