Lucene search

K
redhatcveRedhat.comRH:CVE-2021-46795
HistoryJan 25, 2023 - 1:05 p.m.

CVE-2021-46795

2023-01-2513:05:39
redhat.com
access.redhat.com
34
cve-2021-46795
time-of-check to time-of-use
bios compromise
tee memory read
denial of service
amd

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.7%

A Time-of-check to time-of-use (TOCTOU) vulnerability exists in hw. This flaw allows an attacker to use a compromised BIOS to cause the trusted execution environment (TEE) operating system to read memory out-of-bounds, potentially resulting in a denial of service.

Mitigation

Please contact AMD for more updates on this flaw.

CVSS3

4.7

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.7%

Related for RH:CVE-2021-46795