CVE-2024-21944

MEDIUM

Amd Epyc™ 7003 Series Processors - Improper Input Validation

Title source: rule
STIX 2.1

Description

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (4)
AMD/AMD EPYC™ 7003 Series Processors Milan PI 1.0.0.D
AMD/AMD EPYC™ 7003 Series Processors SEV FW 1.55.22 (hex 1.37.16)
AMD/AMD EPYC™ 9004 Series Processor Genoa PI 1.0.0.D
AMD/AMD EPYC™ 9004 Series Processor SEV FW 1.55.38 (hex 1.37.26)
Published Jun 10, 2026
Tracked Since Jun 11, 2026