CVE-2021-46766

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amd:epyc_9654p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9654p:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amd:epyc_9654_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9654:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amd:epyc_9634_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9634:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amd:epyc_9554p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9554p:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amd:epyc_9554_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9554:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amd:epyc_9534_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9534:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amd:epyc_9474f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9474f:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amd:epyc_9454p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9454p:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amd:epyc_9454_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9454:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amd:epyc_9374f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9374f:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amd:epyc_9354p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9354p:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amd:epyc_9354_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9354:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amd:epyc_9334_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9334:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amd:epyc_9274f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9274f:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:amd:epyc_9254_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9254:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:amd:epyc_9224_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9224:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:amd:epyc_9174f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9174f:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:amd:epyc_9124_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9124:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:amd:epyc_9684x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9684x:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:amd:epyc_9384x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9384x:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:amd:epyc_9184x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9184x:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:amd:epyc_9754_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9754:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:amd:epyc_9754s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9754s:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:amd:epyc_9734_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9734:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_pro_3995wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3995wx:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_pro_3975wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3975wx:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_pro_3955wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3955wx:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_pro_3945wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3945wx:-:*:*:*:*:*:*:*

History

18 Jun 2024, 19:15

Type Values Removed Values Added
Summary (en) Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality. (en) Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

13 Feb 2024, 20:15

Type Values Removed Values Added
References
  • () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001 -

27 Nov 2023, 19:01

Type Values Removed Values Added
References () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002 - () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4002 - Vendor Advisory
References () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002 - () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Amd epyc 9534 Firmware
Amd ryzen Threadripper Pro 3975wx Firmware
Amd ryzen Threadripper Pro 3945wx Firmware
Amd epyc 9684x Firmware
Amd epyc 9654 Firmware
Amd epyc 9174f
Amd epyc 9654
Amd epyc 9454p Firmware
Amd epyc 9754
Amd epyc 9554p Firmware
Amd epyc 9474f Firmware
Amd epyc 9454 Firmware
Amd epyc 9184x Firmware
Amd ryzen Threadripper Pro 3945wx
Amd epyc 9384x
Amd epyc 9224 Firmware
Amd epyc 9554p
Amd epyc 9354p Firmware
Amd epyc 9474f
Amd epyc 9254 Firmware
Amd epyc 9534
Amd epyc 9374f Firmware
Amd epyc 9634 Firmware
Amd epyc 9754s
Amd epyc 9354p
Amd epyc 9554
Amd ryzen Threadripper Pro 3955wx
Amd epyc 9384x Firmware
Amd epyc 9174f Firmware
Amd ryzen Threadripper Pro 3975wx
Amd ryzen Threadripper Pro 3995wx Firmware
Amd epyc 9354 Firmware
Amd epyc 9274f
Amd epyc 9654p
Amd ryzen Threadripper Pro 3955wx Firmware
Amd epyc 9334
Amd epyc 9224
Amd epyc 9184x
Amd epyc 9254
Amd
Amd epyc 9274f Firmware
Amd epyc 9734
Amd ryzen Threadripper Pro 3995wx
Amd epyc 9124 Firmware
Amd epyc 9634
Amd epyc 9354
Amd epyc 9454
Amd epyc 9734 Firmware
Amd epyc 9124
Amd epyc 9334 Firmware
Amd epyc 9684x
Amd epyc 9374f
Amd epyc 9454p
Amd epyc 9654p Firmware
Amd epyc 9754s Firmware
Amd epyc 9554 Firmware
Amd epyc 9754 Firmware
CPE cpe:2.3:h:amd:epyc_9274f:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9454p:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9174f:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9454p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3945wx:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9184x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9634:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9654p:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9684x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9354p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9474f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3995wx:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9334:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9554p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9654p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9474f:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9254:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9174f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9534:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9274f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9754s:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9124_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9354:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9184x:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9554_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_threadripper_pro_3945wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9534_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9354_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9684x:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_threadripper_pro_3955wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9654:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9734_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9334_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9384x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9734:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9374f:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9634_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9224_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9384x:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9754:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_threadripper_pro_3995wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3955wx:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9454_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9754_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_pro_3975wx:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9354p:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9374f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9654_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9124:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9754s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9554:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9454:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_threadripper_pro_3975wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9224:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_9254_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_9554p:-:*:*:*:*:*:*:*
CWE CWE-459

14 Nov 2023, 19:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-14 19:15

Updated : 2024-06-18 19:15


NVD link : CVE-2021-46766

Mitre link : CVE-2021-46766

CVE.ORG link : CVE-2021-46766


JSON object : View

Products Affected

amd

  • epyc_9654p_firmware
  • epyc_9374f_firmware
  • epyc_9184x
  • epyc_9474f_firmware
  • epyc_9554_firmware
  • epyc_9654_firmware
  • epyc_9384x_firmware
  • epyc_9454p
  • epyc_9554
  • ryzen_threadripper_pro_3945wx_firmware
  • epyc_9224_firmware
  • epyc_9734
  • epyc_9734_firmware
  • epyc_9374f
  • epyc_9334_firmware
  • ryzen_threadripper_pro_3995wx
  • epyc_9274f
  • epyc_9454
  • ryzen_threadripper_pro_3955wx_firmware
  • ryzen_threadripper_pro_3945wx
  • epyc_9124
  • epyc_9354p_firmware
  • epyc_9184x_firmware
  • ryzen_threadripper_pro_3995wx_firmware
  • epyc_9124_firmware
  • epyc_9224
  • epyc_9354_firmware
  • epyc_9174f
  • epyc_9654
  • epyc_9654p
  • epyc_9384x
  • epyc_9554p
  • epyc_9754_firmware
  • epyc_9754s
  • epyc_9534_firmware
  • epyc_9274f_firmware
  • epyc_9534
  • epyc_9754s_firmware
  • epyc_9634
  • epyc_9334
  • epyc_9254_firmware
  • epyc_9554p_firmware
  • epyc_9254
  • epyc_9354
  • ryzen_threadripper_pro_3975wx
  • epyc_9684x_firmware
  • epyc_9684x
  • ryzen_threadripper_pro_3975wx_firmware
  • epyc_9354p
  • ryzen_threadripper_pro_3955wx
  • epyc_9454p_firmware
  • epyc_9634_firmware
  • epyc_9454_firmware
  • epyc_9174f_firmware
  • epyc_9474f
  • epyc_9754
CWE
CWE-459

Incomplete Cleanup