CVE-2024-21981
Last modified
CVE-2024-21981 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-21981?
How severe is CVE-2024-21981?
How do I fix CVE-2024-21981?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-21976Improper input validation in the NPU driver could allow an a…8.8
- CVE-2024-21977Incomplete cleanup after loading a CPU microcode patch may a…3.2
- CVE-2024-21978Improper input validation in SEV-SNP could allow a malicious…7.9
- CVE-2024-21979 An out of bounds write vulnerability in the AMD Radeon™ use…5.3
- CVE-2024-2198The Contact Form by BestWebSoft plugin for WordPress is vuln…6.1
- CVE-2024-21980Improper restriction of write operations in SNP firmware cou…7.9
- CVE-2024-21982ONTAP versions 9.4 and higher are susceptible to a vulnerabi…6.5
- CVE-2024-21983StorageGRID (formerly StorageGRID Webscale) versions prior t…6.5
- CVE-2024-21984StorageGRID (formerly StorageGRID Webscale) versions prior t…6.9
- CVE-2024-21985ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.…7.6
- CVE-2024-21987SnapCenter versions 4.8 prior to 5.0 are susceptible to a v…5.4
- CVE-2024-21988StorageGRID (formerly StorageGRID Webscale) versions prior t…5.3
Are you affected by CVE-2024-21981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
