CVE-2024-21980

Aug. 5, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

AMD Secure Processor (SNP firmware)

Source

psirt@amd.com

Tags

CVE-2024-21980 details

Published : Aug. 5, 2024, 4:15 p.m.
Last Modified : Aug. 5, 2024, 4:15 p.m.

Description

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

CVSS Score

1 2 3 4 5 6 7.9 8 9 10

Weakness

Weakness Name Description
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer The product performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

CVSS Data

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

7.9

Exploitability Score

1.5

Impact Score

5.8

Base Severity

HIGH

This website uses the NVD API, but is not approved or certified by it.