CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
Percentile
12.6%
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
Vendor | Product | Version | CPE |
---|---|---|---|
amd | epyc_7001 | - | cpe:2.3:h:amd:epyc_7001:-:*:*:*:*:*:*:* |
amd | epyc_7001_firmware | - | cpe:2.3:o:amd:epyc_7001_firmware:-:*:*:*:*:*:*:* |
amd | epyc_7002 | - | cpe:2.3:h:amd:epyc_7002:-:*:*:*:*:*:*:* |
amd | epyc_7002_firmware | - | cpe:2.3:o:amd:epyc_7002_firmware:-:*:*:*:*:*:*:* |
amd | epyc_7003 | - | cpe:2.3:h:amd:epyc_7003:-:*:*:*:*:*:*:* |
amd | epyc_7003_firmware | - | cpe:2.3:o:amd:epyc_7003_firmware:-:*:*:*:*:*:*:* |
amd | epyc_7232p | - | cpe:2.3:h:amd:epyc_7232p:-:*:*:*:*:*:*:* |
amd | epyc_7232p_firmware | - | cpe:2.3:o:amd:epyc_7232p_firmware:-:*:*:*:*:*:*:* |
amd | epyc_7251 | - | cpe:2.3:h:amd:epyc_7251:-:*:*:*:*:*:*:* |
amd | epyc_7251_firmware | - | cpe:2.3:o:amd:epyc_7251_firmware:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS
Percentile
12.6%