CVE-2021-26356

A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.








TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
AMDCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
amdryzen_9_3950x_firmware
-
amdryzen_9_3950xt_firmware
-
amdryzen_9_3900_firmware
-
amdryzen_9_3900x_firmware
-
amdryzen_7_3800x_firmware
-
amdryzen_7_3800xt_firmware
-
amdryzen_7_3700xt_firmware
-
amdryzen_5_3600x_firmware
-
amdryzen_5_3600xt_firmware
-
amdryzen_5_3600_firmware
-
amdryzen_5_3500x_firmware
-
amdryzen_5_3500_firmware
-
amdryzen_3_3300x_firmware
-
amdryzen_3_3100_firmware
-
amdryzen_threadripper_3990x_firmware
-
amdryzen_threadripper_3970x_firmware
-
amdryzen_threadripper_3960x_firmware
-
amdryzen_threadripper_pro_3995wx_firmware
-
amdryzen_threadripper_pro_3975wx_firmware
-
amdryzen_threadripper_pro_3955wx_firmware
-
amdryzen_threadripper_pro_3945wx_firmware
-
amdryzen_threadripper_pro_5955wx_firmware
-
amdryzen_threadripper_pro_5965wx_firmware
-
amdryzen_threadripper_pro_5945wx_firmware
-
amdryzen_threadripper_pro_5975wx_firmware
-
amdryzen_threadripper_pro_5995wx_firmware
-
𝑥
= Vulnerable software versions