Insufficient input validation in the ASP (AMD Secure...
Critical severity
Unreviewed
Published
May 9, 2023
to the GitHub Advisory Database
•
Updated Feb 22, 2024
Description
Published by the National Vulnerability Database
May 9, 2023
Published to the GitHub Advisory Database
May 9, 2023
Last updated
Feb 22, 2024
Insufficient input validation in the ASP (AMD
Secure Processor) bootloader may allow an attacker with a compromised Uapp or
ABL to coerce the bootloader into exposing sensitive information to the SMU
(System Management Unit) resulting in a potential loss of confidentiality and
integrity.
References