CVE-2021-46753
high-risk
Published 2023-05-09
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.
Do I need to act?
-
0.24% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.1/10
Critical
NETWORK
/ LOW complexity
Affected Products (20)
Ryzen 2600X Firmware
Ryzen 2700 Firmware
Ryzen 2700 Firmware
Ryzen 2700 Firmware
Ryzen 2700 Firmware
Ryzen 2700E Firmware
Ryzen 2700E Firmware
Ryzen 2700E Firmware
Ryzen 2700E Firmware
Ryzen 2700X Firmware
Ryzen 2700X Firmware
Ryzen 2700X Firmware
Ryzen 2700X Firmware
Ryzen 2920X Firmware
Ryzen 2920X Firmware
Ryzen 2920X Firmware
Ryzen 2920X Firmware
Ryzen 2950X Firmware
Ryzen 2950X Firmware
Ryzen 2950X Firmware
Affected Vendors
References (2)
65
/ 100
high-risk
Severity
31/34 · Critical
Exploitability
1/34 · Minimal
Exposure
33/34 · Critical