PT-2023-1406 · Amd · Amd Processors
Cfir Cohen
+2
·
Published
2023-01-10
·
Updated
2023-01-18
·
CVE-2021-26328
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
AMD processors (affected versions not specified)
Description
The issue is related to insufficient input validation in the implementation of the SNP INIT command for the AMD processor firmware loading mode. This could allow a remote attacker to compromise the integrity of protected information. Additionally, failure to verify the CPU execution mode during SNP INIT may lead to potential memory integrity loss for SNP guests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improperly Implemented Security Check for Standard
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amd Processors