Improper access control in AMD products - CVE-2021-26387

 

Improper access control in AMD products - CVE-2021-26387

Published: October 2, 2024


Vulnerability identifier: #VU97952
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26387
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper access restrictions in ASP kernel. A local privileged user with access to AMD signing keys and the BIOS menu or UEFI shell can map DRAM regions in protected areas.


Affected software

1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
4th Gen AMD EPYC Processors
SimpliVity 325 Gen10 Plus
SimpliVity 325 Gen10
SimpliVity 325 Gen 11
HPE ProLiant DL345 Gen11 Server
HPE Gen11 BIOS
HPE ProLiant DL385 Gen11 Server
HPE ProLiant DL365 Gen11 Server
HPE ProLiant DL325 Gen11 Server
HPE ProLiant DL325 Gen10 Plus v2 server
HPE ProLiant DL345 Gen10 Plus server
HPE ProLiant DL365 Gen10 Plus server
HPE ProLiant DL385 Gen10 Plus server
HPE ProLiant DL385 Gen10 Plus v2 server
HPE ProLiant DL325 Gen10 Plus server
HPE Gen10 Plus BIOS
HPE ProLiant DL325 Gen10 Server
HPE ProLiant DL385 Gen10 Server
HPE Gen10 BIOS

How to mitigate CVE-2021-26387

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

The vendor is not planning to release security fixes to address this vulnerability.


SimpliVity 325 Gen10 Plus - update to SVTSPGen10-2024_0731
SimpliVity 325 Gen10 - update to SVTSPGen10-2024_0731
SimpliVity 325 Gen 11 - update to SVTSPGen11-2024_0731
HPE ProLiant DL345 Gen11 Server - update to 1.58_01-04-2024
HPE Gen11 BIOS - update to 1.58_01-04-2024
HPE ProLiant DL385 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL365 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL325 Gen11 Server - update to 1.58_01-04-2024
HPE ProLiant DL325 Gen10 Plus v2 server - update to 2.84_08-17-2023
HPE ProLiant DL345 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL365 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL385 Gen10 Plus server - update to 2.84_08-17-2023
HPE ProLiant DL385 Gen10 Plus v2 server - update to 2.84_08-17-2023
HPE ProLiant DL325 Gen10 Plus server - update to 2.84_08-17-2023
HPE Gen10 Plus BIOS - update to 2.84_08-17-2023
HPE ProLiant DL325 Gen10 Server - update to 2.84_09-07-2023
HPE ProLiant DL385 Gen10 Server - update to 2.84_09-07-2023
HPE Gen10 BIOS - update to 2.84_09-07-2023

External References

Related Security Bulletins