Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gp8r-64c4-ggqw

Опубликовано: 09 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

EPSS

Процентиль: 18%
0.00057
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

EPSS

Процентиль: 18%
0.00057
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-787