PT-2023-1484 · Amd · Amd Secure Encrypted Virtualization
CVE-2021-26403
·
Publicado
2023-01-10
·
Atualizado
2025-04-08
CVSS v3.1
6.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AMD Secure Encrypted Virtualization (SEV) (affected versions not specified)
Description
The issue is related to insufficient input validation in the implementation of AMD Secure Encrypted Virtualization (SEV) microcode in AMD processors. This could allow an attacker to gain unauthorized access to protected information. Specifically, insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret, potentially resulting in the compromise of VM confidentiality.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Amd Secure Encrypted Virtualization