An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
History

Tue, 13 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd milanpi
Amd naplespi
Amd romepi
CPEs cpe:2.3:h:amd:milanpi:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:naplespi:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:romepi:-:*:*:*:*:*:*:*
Vendors & Products Amd
Amd milanpi
Amd naplespi
Amd romepi
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
Description An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published: 2024-08-13T16:49:52.889Z

Updated: 2024-08-13T18:33:40.359Z

Reserved: 2021-01-29T21:24:26.145Z

Link: CVE-2021-26344

cve-icon Vulnrichment

Updated: 2024-08-13T18:33:28.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-13T17:15:17.113

Modified: 2024-08-14T02:07:05.410

Link: CVE-2021-26344

cve-icon Redhat

No data.