Vulnerabilities > CVE-2021-26343 - Exposure of Resource to Wrong Sphere vulnerability in AMD products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
amd
CWE-668

Summary

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

Vulnerable Configurations

Part Description Count
OS
Amd
109
Hardware
Amd
24

Common Weakness Enumeration (CWE)