CVE-2021-46758

MEDIUM

AMD Ryzen Firmware - Memory Read via SPI Flash Address Validation Bypass

Title source: llm
STIX 2.1

Description

Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

Status published
Products (50)
amd/ryzen_3_4300u_firmware < renoirpi-fp6_1.0.0.a
amd/ryzen_3_5125c_firmware < cezannepi-fp6_1.0.0.c
amd/ryzen_3_5300g_firmware < comboam4v2_pi_1.2.0.8
amd/ryzen_3_5300ge_firmware < comboam4v2_pi_1.2.0.8
amd/ryzen_3_5300u_firmware < cezannepi-fp6_1.0.0.c
amd/ryzen_3_5400u_firmware < cezannepi-fp6_1.0.0.c
amd/ryzen_3_5425u_firmware < cezannepi-fp6_1.0.0.c
amd/ryzen_3_7335u_firmware < rembrandtpi-fp7_1.0.0.5
amd/ryzen_3_pro_7330u_firmware < cezannepi-fp6_1.0.0.c
amd/ryzen_5_4500u_firmware < renoirpi-fp6_1.0.0.a
... and 40 more
Published Nov 14, 2023
Tracked Since Feb 18, 2026