CVE-2021-26370

Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amd:epyc_7763_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7763:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amd:epyc_7713p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7713p:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amd:epyc_7713_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7713:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amd:epyc_7663_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7663:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amd:epyc_7643_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7643:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amd:epyc_75f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_75f3:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amd:epyc_7543p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7543p:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amd:epyc_7543_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7543:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amd:epyc_7513_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7513:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amd:epyc_7453_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7453:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amd:epyc_74f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_74f3:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amd:epyc_7443p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7443p:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amd:epyc_7443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7443:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amd:epyc_7413_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7413:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:amd:epyc_73f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_73f3:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:amd:epyc_7343_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7343:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:amd:epyc_7313p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7313p:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:amd:epyc_7313_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7313:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:amd:epyc_72f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_72f3:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:amd:epyc_7773x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7773x:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:amd:epyc_7473x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7473x:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:amd:epyc_7573x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7573x:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:amd:epyc_7373x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7373x:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:amd:epyc_7002_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7002:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:amd:epyc_7232p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7232p:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:amd:epyc_7252_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7252:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:amd:epyc_7262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7262:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:amd:epyc_7272_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7272:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:amd:epyc_7282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7282:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:amd:epyc_7302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7302:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:amd:epyc_7302p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7302p:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:amd:epyc_7352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7352:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:amd:epyc_7402_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7402:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:amd:epyc_7402p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7402p:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:amd:epyc_7452_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7452:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:amd:epyc_7502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7502:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:amd:epyc_7502p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7502p:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:amd:epyc_7532_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7532:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:amd:epyc_7542_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7542:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:amd:epyc_7552_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7552:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:amd:epyc_7642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7642:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:amd:epyc_7662_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7662:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:amd:epyc_7702_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7702:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:amd:epyc_7702p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7702p:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:amd:epyc_7742_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7742:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:amd:epyc_7f72_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f72:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:amd:epyc_7f52_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f52:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:amd:epyc_7f32_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f32:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:amd:epyc_7h12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7h12:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-05-10 19:15

Updated : 2024-02-28 19:09


NVD link : CVE-2021-26370

Mitre link : CVE-2021-26370

CVE.ORG link : CVE-2021-26370


JSON object : View

Products Affected

amd

  • epyc_7543_firmware
  • epyc_7763
  • epyc_7f32_firmware
  • epyc_7642
  • epyc_7702_firmware
  • epyc_72f3
  • epyc_7313
  • epyc_7402
  • epyc_7373x
  • epyc_7302
  • epyc_7002_firmware
  • epyc_7272_firmware
  • epyc_7313p
  • epyc_7402p_firmware
  • epyc_7502_firmware
  • epyc_7542_firmware
  • epyc_7282
  • epyc_7302p_firmware
  • epyc_7232p_firmware
  • epyc_74f3_firmware
  • epyc_7402_firmware
  • epyc_7313_firmware
  • epyc_7262
  • epyc_7452
  • epyc_7373x_firmware
  • epyc_7302p
  • epyc_7552
  • epyc_7543
  • epyc_7453
  • epyc_73f3
  • epyc_7453_firmware
  • epyc_7443p
  • epyc_7543p
  • epyc_74f3
  • epyc_73f3_firmware
  • epyc_7513_firmware
  • epyc_7452_firmware
  • epyc_7443p_firmware
  • epyc_7343
  • epyc_7272
  • epyc_7643
  • epyc_7713p
  • epyc_7502
  • epyc_75f3
  • epyc_7f52_firmware
  • epyc_75f3_firmware
  • epyc_7352
  • epyc_7713
  • epyc_7262_firmware
  • epyc_7302_firmware
  • epyc_7573x
  • epyc_7f72_firmware
  • epyc_7443
  • epyc_7642_firmware
  • epyc_7742_firmware
  • epyc_7513
  • epyc_7473x_firmware
  • epyc_7742
  • epyc_7443_firmware
  • epyc_7763_firmware
  • epyc_7552_firmware
  • epyc_7252
  • epyc_7f32
  • epyc_7282_firmware
  • epyc_7542
  • epyc_7662_firmware
  • epyc_7713p_firmware
  • epyc_7002
  • epyc_7473x
  • epyc_7502p_firmware
  • epyc_7402p
  • epyc_7352_firmware
  • epyc_7663_firmware
  • epyc_7573x_firmware
  • epyc_7413
  • epyc_7643_firmware
  • epyc_7413_firmware
  • epyc_7313p_firmware
  • epyc_7f72
  • epyc_72f3_firmware
  • epyc_7702p_firmware
  • epyc_7f52
  • epyc_7h12
  • epyc_7252_firmware
  • epyc_7343_firmware
  • epyc_7232p
  • epyc_7773x
  • epyc_7773x_firmware
  • epyc_7702p
  • epyc_7532
  • epyc_7713_firmware
  • epyc_7702
  • epyc_7502p
  • epyc_7662
  • epyc_7532_firmware
  • epyc_7h12_firmware
  • epyc_7543p_firmware
  • epyc_7663
CWE
CWE-20

Improper Input Validation