PT-2023-1488 · Amd · Amd Secure Encrypted Virtualization+2

Published

2023-01-10

·

Updated

2025-04-08

·

CVE-2021-26407

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AMD Secure Processor (ASP) (affected versions not specified) AMD System Management Unit (SMU) (affected versions not specified) AMD Secure Encrypted Virtualization (SEV) (affected versions not specified)
Description The issue is related to errors in initialization, which may lead to information disclosure. A collision of Initialization Vectors (IVs) with the same key could potentially result in the disclosure of protected information.
Recommendations For AMD Secure Processor (ASP), consider implementing proper initialization procedures to prevent errors. For AMD System Management Unit (SMU), ensure that all initialization processes are thoroughly reviewed and validated to prevent potential information disclosure. For AMD Secure Encrypted Virtualization (SEV), as a temporary workaround, consider restricting access to sensitive information until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

Information Disclosure

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00898
CVE-2021-26407

Affected Products

Amd Secure Encrypted Virtualization
Amd Secure Processor
Amd System Management Unit