Description
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.
CVSS breakdown
CVSS 4.0
Attack Vector
Local
Attack Complexity
High
Attack Requirements
None
Privileges Required
High
User Interaction
None
Confidentiality (Vulnerable System)
None
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
None
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
Affected products
- AMD / AMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsComboAM4v2PI 1.2.0.CA – ComboAM4v2PI 1.2.0.CA
- AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsPollock-FT5 1.0.0.7 – Pollock-FT5 1.0.0.7
- AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsPicasso-FP5 1.0.1.1 – Picasso-FP5 1.0.1.1
- AMD / AMD Ryzen™ 3000 Series Desktop ProcessorsComboAM4v2PI 1.2.0.CA – ComboAM4v2PI 1.2.0.CA
- AMD / AMD Ryzen™ 3000 Series Desktop ProcessorsComboAM4PI 1.0.0.F – ComboAM4PI 1.0.0.F
- AMD / AMD Ryzen™ 4000 Series Desktop ProcessorsComboAM4v2PI 1.2.0.CA – ComboAM4v2PI 1.2.0.CA
- AMD / AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsRenoir-FP6 1.0.0.D – Renoir-FP6 1.0.0.D
- AMD / AMD Ryzen™ 5000 Series Desktop ProcessorsComboAM4v2PI 1.2.0.CA – ComboAM4v2PI 1.2.0.CA
- AMD / AMD Ryzen™ 5000 Series Processors with Radeon™ GraphicsCezanne-FP6 1.0.1.0 – Cezanne-FP6 1.0.1.0
- AMD / AMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsRembrandt-FP7 1.0.0.A – Rembrandt-FP7 1.0.0.A
- AMD / AMD Ryzen™ 7000 Series Desktop ProcessorsComboAM5 1.0.0.7a – ComboAM5 1.0.0.7a
- AMD / AMD Ryzen™ 7020 Series Processors with Radeon™ GraphicsMendocinoPI-FT6 1.0.0.6 – MendocinoPI-FT6 1.0.0.6
- AMD / AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ GraphicsCezanne-FP6 1.0.1.0 – Cezanne-FP6 1.0.1.0
- AMD / AMD Ryzen™ 8000 Series Desktop ProcessorsComboAM5 1.0.0.7a – ComboAM5 1.0.0.7a
- AMD / AMD Ryzen™ Threadripper™ 3000 Series ProcessorsCastlePeakPI-SP3r3 1.0.0.C – CastlePeakPI-SP3r3 1.0.0.C
- AMD / AMD Ryzen™ Threadripper™ 7000 ProcessorsStormPeakPI-SP6 1.1.0.0c – StormPeakPI-SP6 1.1.0.0c
- AMD / AMD Ryzen™ Threadripper™ PRO 3000WX Series ProcessorsCastlePeakWSPI-sWRX8 1.0.0.E – CastlePeakWSPI-sWRX8 1.0.0.E
- AMD / AMD Ryzen™ Threadripper™ PRO 5000 WX-Series ProcessorsChagallWSPI-sWRX8 1.0.0.9 – ChagallWSPI-sWRX8 1.0.0.9
- AMD / AMD Ryzen™ Threadripper™ PRO 7000WX-Series ProcessorsStormPeakPI-SP6 1.0.0.1e – StormPeakPI-SP6 1.0.0.1e