Description
Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
Low
Affected products
- AMD / AMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsComboAM4PI 1.0.0.9 – ComboAM4PI 1.0.0.9
- AMD / AMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsComboAM4v2 PI 1.2.0.8 – ComboAM4v2 PI 1.2.0.8
- AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsPicassoPI-FP5 1.0.0.E – PicassoPI-FP5 1.0.0.E
- AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsPollockPI-FT5 1.0.0.4 – PollockPI-FT5 1.0.0.4
- AMD / AMD EPYC™ 7001 Series Processorsvarious – various
- AMD / AMD EPYC™ 7002 Series Processorsvarious – various
- AMD / AMD EPYC™ 7003 Series Processorsvarious – various
- AMD / AMD EPYC™ 9004 Series Processorsvarious – various
- AMD / AMD EPYC™ Embedded 3000 Series Processorsvarious – various
- AMD / AMD EPYC™ Embedded 7002 Series Processorsvarious – various
- AMD / AMD EPYC™ Embedded 7003 Series Processorsvarious – various
- AMD / AMD EPYC™ Embedded 9003 Series Processorsvarious – various
- AMD / AMD Ryzen™ 3000 Series Desktop ProcessorsComboAM4 V2 PI 1.2.0.8 – ComboAM4 V2 PI 1.2.0.8
- AMD / AMD Ryzen™ 3000 Series Desktop ProcessorsComboAM4PI 1.0.0.9 – ComboAM4PI 1.0.0.9
- AMD / AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ GraphicsPicassoPI-FP5 1.0.0.E – PicassoPI-FP5 1.0.0.E
- AMD / AMD Ryzen™ 3000 Series Processors with Radeon™ GraphicsCezannePI-FP6 1.0.0.9 – CezannePI-FP6 1.0.0.9
- AMD / AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ GraphicsComboAM4v2 PI 1.2.0.5 – ComboAM4v2 PI 1.2.0.5
- AMD / AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsRenoirPI-FP6 1.0.0.8 – RenoirPI-FP6 1.0.0.8
- AMD / AMD Ryzen™ 5000 Series Desktop ProcessorsComboAM4 V2 PI 1.2.0.8 – ComboAM4 V2 PI 1.2.0.8
- AMD / AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ GraphicsComboAM4v2 PI 1.2.0.6 – ComboAM4v2 PI 1.2.0.6
- AMD / AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsCezannePI-FP6 1.0.0.9 – CezannePI-FP6 1.0.0.9
- AMD / AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsCezannePI-FP6 1.0.0.9 – CezannePI-FP6 1.0.0.9
- AMD / AMD Ryzen™ 5000 Series Processors with Radeon™ GraphicsCezannePI-FP6 1.0.0.9 – CezannePI-FP6 1.0.0.9
- AMD / AMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsRembrandtPI-FP7 1.0.0.9b – RembrandtPI-FP7 1.0.0.9b
- AMD / AMD Ryzen™ 7000 Series Desktop ProcessorsComboAM5 1.0.8.0 – ComboAM5 1.0.8.0
- AMD / AMD Ryzen™ 7035 Series Processors with Radeon™ GraphicsRembrandtPI-FP7 1.0.0.9b – RembrandtPI-FP7 1.0.0.9b
- AMD / AMD Ryzen™ Embedded 5000 Series ProcessorsEmbAM4PI 1.0.0.2 – EmbAM4PI 1.0.0.2
- AMD / AMD Ryzen™ Embedded R1000 Series ProcessorsEmbeddedPI-FP5 1.2.0.A – EmbeddedPI-FP5 1.2.0.A
- AMD / AMD Ryzen™ Embedded R2000 Series ProcessorsEmbeddedR2KPI-FP5 1.0.0.2 – EmbeddedR2KPI-FP5 1.0.0.2
- AMD / AMD Ryzen™ Embedded V1000 Series ProcessorsEmbeddedPI-FP5 1.2.0.A – EmbeddedPI-FP5 1.2.0.A
- AMD / AMD Ryzen™ Embedded V2000 Series ProcessorsEmbeddedPI-FP6 1.0.0.6 – EmbeddedPI-FP6 1.0.0.6
- AMD / AMD Ryzen™ Embedded V3000 Series ProcessorsEmbeddedPI-FP7r2 1.0.0.9 – EmbeddedPI-FP7r2 1.0.0.9
- AMD / AMD Ryzen™ Threadripper™ 3000 Series ProcessorsCastlePeakPI-SP3r3 1.0.0.7 – CastlePeakPI-SP3r3 1.0.0.7
- AMD / AMD Ryzen™ Threadripper™ PRO 3000WX Series ProcessorsChagallWSPI-sWRX8 1.0.0.2 – ChagallWSPI-sWRX8 1.0.0.2
- AMD / AMD Ryzen™ Threadripper™ PRO 3000WX Series ProcessorsCastlePeakWSPI-sWRX8 1.0.0.9 – CastlePeakWSPI-sWRX8 1.0.0.9
- AMD / AMD Ryzen™ Threadripper™ PRO 5000WX ProcessorsChagallWSPI-sWRX8 1.0.0.2 – ChagallWSPI-sWRX8 1.0.0.2