Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqvv-8rrx-g836

Опубликовано: 09 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

EPSS

Процентиль: 44%
0.00214
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
nvd
больше 2 лет назад

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

EPSS

Процентиль: 44%
0.00214
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20