PT-2021-17001 · Amd · Amd Platform Security Processor

Shawn Hoffman

·

Published

2021-11-16

·

Updated

2021-11-18

·

CVE-2021-26315

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AMD Platform Security Processor (PSP) (affected versions not specified)
Description The issue arises when the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and decrypts an encrypted firmware (FW) image. Due to insufficient verification of the integrity of the decrypted image, it is possible for arbitrary code to be executed in the PSP when encrypted firmware images are used.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26315

Affected Products

Amd Platform Security Processor