Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-19576 Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Amd
Amd athlon
Amd athlon 3000
Amd ryzen
Amd ryzen 3000
Amd ryzen 4000
Amd ryzen 5000
Amd ryzen 6000
Amd ryzen 7000
Amd ryzen 7020
Vendors & Products Amd
Amd athlon
Amd athlon 3000
Amd ryzen
Amd ryzen 3000
Amd ryzen 4000
Amd ryzen 5000
Amd ryzen 6000
Amd ryzen 7000
Amd ryzen 7020

Mon, 08 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Sep 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-09-08T14:51:10.909Z

Reserved: 2024-01-03T16:43:28.699Z

Link: CVE-2024-21970

cve-icon Vulnrichment

Updated: 2025-09-08T14:51:07.339Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-06T18:15:39.287

Modified: 2025-09-08T16:25:38.810

Link: CVE-2024-21970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-09T21:32:01Z