When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

Project Subscriptions

Vendors Products
Epyc 7003 Subscribe
Epyc 7003 Firmware Subscribe
Epyc 72f3 Subscribe
Epyc 72f3 Firmware Subscribe
Epyc 7313 Subscribe
Epyc 7313 Firmware Subscribe
Epyc 7313p Subscribe
Epyc 7313p Firmware Subscribe
Epyc 7343 Subscribe
Epyc 7343 Firmware Subscribe
Epyc 73f3 Subscribe
Epyc 73f3 Firmware Subscribe
Epyc 7413 Subscribe
Epyc 7413 Firmware Subscribe
Epyc 7443 Subscribe
Epyc 7443 Firmware Subscribe
Epyc 7443p Subscribe
Epyc 7443p Firmware Subscribe
Epyc 7453 Subscribe
Epyc 7453 Firmware Subscribe
Epyc 74f3 Subscribe
Epyc 74f3 Firmware Subscribe
Epyc 7513 Subscribe
Epyc 7513 Firmware Subscribe
Epyc 7543 Subscribe
Epyc 7543 Firmware Subscribe
Epyc 7543p Subscribe
Epyc 7543p Firmware Subscribe
Epyc 75f3 Subscribe
Epyc 75f3 Firmware Subscribe
Epyc 7643 Subscribe
Epyc 7643 Firmware Subscribe
Epyc 7663 Subscribe
Epyc 7663 Firmware Subscribe
Epyc 7713 Subscribe
Epyc 7713 Firmware Subscribe
Epyc 7713p Subscribe
Epyc 7713p Firmware Subscribe
Epyc 7763 Subscribe
Epyc 7763 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-13121 When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2024-09-17T01:21:40.952Z

Reserved: 2021-01-29T00:00:00

Link: CVE-2021-26315

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-16T19:15:07.703

Modified: 2024-11-21T05:56:04.683

Link: CVE-2021-26315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses