CVE-2021-46767 describes an insufficient input validation vulnerability in AMD's ASP (AMD Secure Processor) affecting Milan and Rome series firmware. An attacker with physical access could exploit this to achieve unauthorized memory writes, resulting in a loss of data integrity or a denial of service. Rated Medium severity (CVSS 6.1), the vulnerability requires physical access (AV:P) but has low attack complexity (AC:L) and no user interaction (UI:N). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.dCPE matchmatch criteria | cpe:2.3:o:amd:romepi_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.6CPE matchmatch criteria | cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.