CVE-2020-12946

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/11/2021
Last modified:
08/07/2022

Description

Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:epyc_7f72_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7f72:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7f52_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7f52:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7f32_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7f32:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7h12_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7h12:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7742_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7742:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7702_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7702:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7702p_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)
cpe:2.3:h:amd:epyc_7702p:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:epyc_7662_firmware:*:*:*:*:*:*:*:* romepi-sp3_1.0.0.c (excluding)