{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2021-26387","assignerOrgId":"b58fc414-a1e4-4f92-9d70-1add41838648","state":"PUBLISHED","assignerShortName":"AMD","dateReserved":"2021-01-29T21:24:26.161Z","datePublished":"2024-08-13T16:50:22.151Z","dateUpdated":"2024-10-30T17:59:30.394Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","packageName":"PI","product":"AMD EPYC™ 7001 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various","versionType":"PI"}]},{"defaultStatus":"affected","product":"AMD EPYC™ 7002 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD EPYC™ 7003 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD EPYC™ 9004 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 3000 Series Desktop Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM4PI 1.0.0.9"},{"status":"unaffected","version":"ComboAM4 V2 PI 1.2.0.8"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 5000 Series Desktop Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM4 V2 PI 1.2.0.8"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM4v2 PI 1.2.0.6"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 7000 Series Desktop Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM5 1.0.8.0"}]},{"defaultStatus":"affected","product":"AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM4PI 1.0.0.9"},{"status":"unaffected","version":"ComboAM4v2 PI 1.2.0.8"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"ComboAM4v2 PI 1.2.0.5"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Threadripper™ 3000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"CastlePeakPI-SP3r3  1.0.0.7"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"ChagallWSPI-sWRX8 1.0.0.2"},{"status":"unaffected","version":"CastlePeakWSPI-sWRX8 1.0.0.9"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Threadripper™ PRO 5000WX Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"ChagallWSPI-sWRX8 1.0.0.2"}]},{"defaultStatus":"affected","product":"AMD Athlon™ 3000 Series Mobile  Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"PicassoPI-FP5  1.0.0.E"}]},{"defaultStatus":"affected","product":"AMD Athlon™ 3000 Series Mobile  Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"PollockPI-FT5  1.0.0.4"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"PicassoPI-FP5  1.0.0.E"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"RenoirPI-FP6  1.0.0.8"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"CezannePI-FP6 1.0.0.9"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"CezannePI-FP6  1.0.0.9"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"RembrandtPI-FP7 1.0.0.9b"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"RembrandtPI-FP7 1.0.0.9b"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"CezannePI-FP6 1.0.0.9"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ 3000 Series Processors with Radeon™ Graphics","vendor":"AMD","versions":[{"status":"unaffected","version":"CezannePI-FP6 1.0.0.9"}]},{"defaultStatus":"affected","product":"AMD EPYC™ Embedded 3000 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD EPYC™ Embedded 7002 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD EPYC™ Embedded 7003 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD EPYC™ Embedded 9003 Series Processors","vendor":"AMD","versions":[{"status":"affected","version":"various"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded R1000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbeddedPI-FP5 1.2.0.A"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded R2000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbeddedR2KPI-FP5 1.0.0.2"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded 5000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbAM4PI  1.0.0.2"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded V1000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbeddedPI-FP5 1.2.0.A"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded V2000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbeddedPI-FP6 1.0.0.6"}]},{"defaultStatus":"affected","product":"AMD Ryzen™ Embedded V3000 Series Processors","vendor":"AMD","versions":[{"status":"unaffected","version":"EmbeddedPI-FP7r2 1.0.0.9"}]}],"datePublic":"2024-08-13T16:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: rgb(255, 255, 255);\">Insufficient access controls in ASP kernel may allow a\nprivileged attacker with access to AMD signing keys and the BIOS menu or UEFI\nshell to map DRAM regions in protected <a target=\"_blank\" rel=\"nofollow\">areas,</a>&nbsp;potentially leading to a loss of platform integrity.<div><div><div>\n\n</div>\n\n</div>\n\n</div>\n\n\n\n\n\n</span>"}],"value":"Insufficient access controls in ASP kernel may allow a\nprivileged attacker with access to AMD signing keys and the BIOS menu or UEFI\nshell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"LOW","baseScore":3.9,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"orgId":"b58fc414-a1e4-4f92-9d70-1add41838648","shortName":"AMD","dateUpdated":"2024-08-13T16:50:22.151Z"},"references":[{"tags":["vendor-advisory"],"url":"https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3003.html"},{"url":"https://www.amd.com/en/resources/product-security/bulletin/amd-sb-5002.html"}],"source":{"advisory":"AMD-SB-4002, AMD-SB-3002, AMD-SB-5001","discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-863","lang":"en","description":"CWE-863 Incorrect Authorization"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-08-14T15:47:34.441746Z","id":"CVE-2021-26387","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-30T17:59:30.394Z"}}]}}