CVE-2021-46772

LOW

ABL - Memory Corruption

Title source: llm
STIX 2.1

Description

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.

Scores

CVSS v3 3.9
EPSS 0.0003
EPSS Percentile 8.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-787
Status published
Products (28)
AMD/AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics various
AMD/AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics various
AMD/AMD EPYC™ 7002 Series Processors RomePI 1.0.0.E
AMD/AMD EPYC™ 7003 Series Processors MilanPI 1.0.0.9
AMD/AMD EPYC™ Embedded 7002 Series Processors EmbRomePI-SP3 1.0.0.8
AMD/AMD EPYC™ Embedded 7003 Series Processors EmbMilanPI-SP3 1.0.0.5
AMD/AMD Ryzen™ 3000 Series Desktop Processors various
AMD/AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics various
AMD/AMD Ryzen™ 3000 Series Processors with Radeon™ Graphics CezannePI-FP6 1.0.0.E
AMD/AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics various
... and 18 more
Published Aug 13, 2024
Tracked Since Feb 18, 2026