CVE-2021-46772
Last modified
CVE-2021-46772 is a low-severity vulnerability rated 3.9/10 on the CVSS scale. Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure headers in SPI ROM causing an out of bounds memory read and write, potentially resulting in memory corruption or denial of service.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2021-46772?
How severe is CVE-2021-46772?
How do I fix CVE-2021-46772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-46765Insufficient input validation in ASP may allow an attacker w…7.5
- CVE-2021-46766Improper clearing of sensitive data in the ASP Bootloader ma…5.5
- CVE-2021-46767Insufficient input validation in the ASP may allow an attack…6.1
- CVE-2021-46768Insufficient input validation in SEV firmware may allow an a…5.5
- CVE-2021-46769Insufficient syscall input validation in the ASP Bootloader …8.8
- CVE-2021-46771Insufficient validation of addresses in AMD Secure Processor…7.8
- CVE-2021-46773Insufficient input validation in ABL may enable a privileged…8.8
- CVE-2021-46774Insufficient DRAM address validation in System Management Un…7.5
- CVE-2021-46775Improper input validation in ABL may enable an attacker with…6.8
- CVE-2021-46778Execution unit scheduler contention may lead to a side chann…5.6
- CVE-2021-46779Insufficient input validation in SVC_ECC_PRIMITIVE system ca…7.1
- CVE-2021-46780The Easy Google Maps WordPress plugin before 1.9.32 does not…6.1
Are you affected by CVE-2021-46772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
