CVE Database
/

CVE-2021-26402

Back to search

CVE-2021-26402

Published: Jan 10, 2023

Modified: Apr 8, 2025

PUBLISHED

Description

Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.

VendorProductVersions

AMD

2nd Gen EPYC

affected
Various

AMD

3rd Gen EPYC

affected
various

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now