« Volver al listado

CVE-2021-46779

Estado: ModificadaAlta (7.1)—

Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-46779",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-46779",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-09T14:47:15.527346Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "1st Gen EPYC",
          "versions": [
            {
              "status": "affected",
              "version": "various "
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "AGESA",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": " AMD",
          "product": "2nd Gen EPYC",
          "versions": [
            {
              "status": "affected",
              "version": "various "
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "AGESA",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "3rd Gen EPYC",
          "versions": [
            {
              "status": "affected",
              "version": "various "
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "AGESA",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-01-11T08:15:13.213",
  "references": [
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.\n"
    },
    {
      "lang": "es",
      "value": "Una validación de entrada insuficiente en la llamada al sistema SVC_ECC_PRIMITIVE en una aplicación de usuario comprometida o ABL puede permitir que un atacante corrompa la memoria del sistema operativo ASP (AMD Secure Processor), lo que puede provocar una posible pérdida de integridad y disponibilidad."
    }
  ],
  "lastModified": "2026-06-17T04:15:33.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:amd:romepi_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56013C45-044C-40B0-9503-7E3928602803",
              "versionEndExcluding": "1.0.0.c"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:amd:romepi:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B936879F-731E-4991-ACBB-16643F629B41"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B11959F6-2A87-48A4-AD17-16A6B00C6BFA",
              "versionEndExcluding": "1.0.0.4"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:amd:milanpi:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F64A4AA-A66B-4B2E-B8F1-F332E3945903"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:amd:naplespi_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB1EE9F8-6AA6-48E1-A5C3-79A1FC70C821",
              "versionEndExcluding": "1.0.0.g"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:amd:naplespi:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9C479ABD-FE0C-4C08-B849-7BD516F03733"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@amd.com"
}