CVE-2021-46779 is a high-severity vulnerability affecting AMD Milan, Naples, and Rome processors, stemming from insufficient input validation in the SVC_ECC_PRIMITIVE system call. An attacker with local access to a compromised user application or ABL could exploit this to corrupt AMD Secure Processor (ASP) OS memory. This could lead to a significant loss of integrity and availability for the affected system. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.cCPE matchmatch criteria | cpe:2.3:o:amd:romepi_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.4CPE matchmatch criteria | cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.0.gCPE matchmatch criteria | cpe:2.3:o:amd:naplespi_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.