CVE-2021-26397
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/05/2023
Last modified:
28/01/2025
Description
Insufficient address validation, may allow an<br />
attacker with a compromised ABL and UApp to corrupt sensitive memory locations<br />
potentially resulting in a loss of integrity or availability.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amd:epyc_72f3_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_72f3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7313_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_7313:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7313p_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_7313p:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7343_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_7343:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7373x_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_7373x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_73f3_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_73f3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7413_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) | |
| cpe:2.3:h:amd:epyc_7413:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:epyc_7443_firmware:*:*:*:*:*:*:*:* | milanpi_1.0.0.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



