Vulnerabilities > CVE-2021-26347 - Improper Validation of Specified Quantity in Input vulnerability in AMD products

047910
CVSS 4.7 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
high complexity
amd
CWE-1284

Summary

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

Vulnerable Configurations

Part Description Count
OS
Amd
113
Hardware
Amd
49