CVE-2021-46778
Last modified
CVE-2021-46778 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amd | Athlon 3050ge Firmware | All versions |
| Amd | Athlon 3150g Firmware | All versions |
| Amd | Athlon 3150ge Firmware | All versions |
| Amd | Epyc 7001 Firmware | All versions |
| Amd | Epyc 7002 Firmware | All versions |
| Amd | Epyc 7003 Firmware | All versions |
| Amd | Epyc 7232p Firmware | All versions |
| Amd | Epyc 7251 Firmware | All versions |
| Amd | Epyc 7252 Firmware | All versions |
| Amd | Epyc 7261 Firmware | All versions |
| Amd | Epyc 7262 Firmware | All versions |
| Amd | Epyc 7272 Firmware | All versions |
| Amd | Epyc 7281 Firmware | All versions |
| Amd | Epyc 7282 Firmware | All versions |
| Amd | Epyc 72f3 Firmware | All versions |
| Amd | Epyc 7301 Firmware | All versions |
| Amd | Epyc 7302 Firmware | All versions |
| Amd | Epyc 7302p Firmware | All versions |
| Amd | Epyc 7313 Firmware | All versions |
| Amd | Epyc 7313p Firmware | All versions |
| Amd | Epyc 7343 Firmware | All versions |
| Amd | Epyc 7351 Firmware | All versions |
| Amd | Epyc 7351p Firmware | All versions |
| Amd | Epyc 7352 Firmware | All versions |
| Amd | Epyc 7371 Firmware | All versions |
| Amd | Epyc 7373x Firmware | All versions |
| Amd | Epyc 73f3 Firmware | All versions |
| Amd | Epyc 7401 Firmware | All versions |
| Amd | Epyc 7401p Firmware | All versions |
| Amd | Epyc 7402 Firmware | All versions |
| Amd | Epyc 7402p Firmware | All versions |
| Amd | Epyc 7413 Firmware | All versions |
| Amd | Epyc 7443 Firmware | All versions |
| Amd | Epyc 7443p Firmware | All versions |
| Amd | Epyc 7451 Firmware | All versions |
| Amd | Epyc 7452 Firmware | All versions |
| Amd | Epyc 7453 Firmware | All versions |
| Amd | Epyc 7473x Firmware | All versions |
| Amd | Epyc 74f3 Firmware | All versions |
| Amd | Epyc 7501 Firmware | All versions |
| Amd | Epyc 7502 Firmware | All versions |
| Amd | Epyc 7502p Firmware | All versions |
| Amd | Epyc 7513 Firmware | All versions |
| Amd | Epyc 7532 Firmware | All versions |
| Amd | Epyc 7542 Firmware | All versions |
| Amd | Epyc 7543 Firmware | All versions |
| Amd | Epyc 7543p Firmware | All versions |
| Amd | Epyc 7551 Firmware | All versions |
| Amd | Epyc 7551p Firmware | All versions |
| Amd | Epyc 7552 Firmware | All versions |
Showing 50 of 179 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-46778?
How severe is CVE-2021-46778?
How do I fix CVE-2021-46778?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-46769Insufficient syscall input validation in the ASP Bootloader …8.8
- CVE-2021-46771Insufficient validation of addresses in AMD Secure Processor…7.8
- CVE-2021-46772Insufficient input validation in the ABL may allow a privile…3.9
- CVE-2021-46773Insufficient input validation in ABL may enable a privileged…8.8
- CVE-2021-46774Insufficient DRAM address validation in System Management Un…7.5
- CVE-2021-46775Improper input validation in ABL may enable an attacker with…6.8
- CVE-2021-46779Insufficient input validation in SVC_ECC_PRIMITIVE system ca…7.1
- CVE-2021-46780The Easy Google Maps WordPress plugin before 1.9.32 does not…6.1
- CVE-2021-46781The Coming Soon by Supsystic WordPress plugin before 1.7.6 d…6.1
- CVE-2021-46782The Pricing Table by Supsystic WordPress plugin before 1.9.5…6.1
- CVE-2021-46784In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x befor…6.5
- CVE-2021-46785The Property module has a vulnerability in permission contro…5.3
Are you affected by CVE-2021-46778?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
