CVE-2021-39298

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/02/2022
Last modified:
24/02/2026

Description

A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hp:z1_entry_tower_g5_workstation_firmware:*:*:*:*:*:*:*:* 02.12.00 (excluding)
cpe:2.3:h:hp:z1_entry_tower_g5_workstation:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z1_entry_tower_g6_workstation_firmware:*:*:*:*:*:*:*:* 02.10.00 (excluding)
cpe:2.3:h:hp:z1_entry_tower_g6_workstation:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z1_g8_tower_desktop_pc_firmware:*:*:*:*:*:*:*:* 02.07.00 (excluding)
cpe:2.3:h:hp:z1_g8_tower_desktop_pc:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:linux_kernel:*:* 02.75 (excluding)
cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:windows_10:*:* 02.75 (excluding)
cpe:2.3:o:hp:z4_g4_workstation_\(core-x\)_firmware:*:*:*:*:*:windows_7:*:* 02.75 (excluding)
cpe:2.3:h:hp:z4_g4_workstation_\(core-x\):-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:linux_kernel:*:* 02.75 (excluding)
cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:windows_10:*:* 02.75 (excluding)
cpe:2.3:o:hp:z4_g4_workstation_\(xeon_w\)_firmware:*:*:*:*:*:windows_7:*:* 02.75 (excluding)
cpe:2.3:h:hp:z4_g4_workstation_\(xeon_w\):-:*:*:*:*:*:*:*
cpe:2.3:o:hp:z6_g4_workstation_firmware:*:*:*:*:*:linux_kernel:*:* 02.75 (excluding)