PT-2024-19135 · Amd+1 · Amd Epyc Embedded 9003 Snp Firmware+1

Published

2024-08-05

·

Updated

2025-08-13

·

CVE-2024-21980

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AMD EPYC Embedded 9003 SNP Firmware (affected versions not specified)
Description The issue is related to improper restriction of write operations in SNP firmware, which could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed. This results in loss of confidentiality and integrity. The exploitation requires local access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09863
CVE-2024-21980

Affected Products

Amd Epyc Embedded 9003 Snp Firmware
Red Os