Description
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
CVSS breakdown
CVSS 3.1
Attack Vector
Physical
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- AMD / 1st Gen AMD EPYC™ Processorsvarious – various
- AMD / 2nd Gen AMD EPYC™ Processorsvarious – various
- AMD / 3rd Gen AMD EPYC™ Processorsvarious – various
- AMD / AMD EPYC™ Embedded 3000various – various
- AMD / AMD EPYC™ Embedded 7002various – various
- AMD / AMD EPYC™ Embedded 7003various – various
- AMD / AMD Ryzen™ Threadripper™ 2000 Series Processors “Colfax”various – various