{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T03:38:22.079","vulnerabilities":[{"cve":{"id":"CVE-2021-46791","sourceIdentifier":"psirt@amd.com","published":"2023-01-11T08:15:13.270","lastModified":"2026-06-17T04:15:34.827","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.\n"},{"lang":"es","value":"Una validación de entrada insuficiente durante el análisis del binario del System Management Mode (SMM) puede permitir que un binario ejecutable de SMM creado con fines malintencionados corrompa la memoria de la aplicación del usuario de la Dynamic Root of Trust for Measurement (DRTM), lo que puede resultar en una posible denegación de servicio."}],"affected":[{"source":"psirt@amd.com","affectedData":[{"vendor":"AMD","product":"3rd Gen EPYC","defaultStatus":"unaffected","packageName":"AGESA","platforms":["x86"],"versions":[{"version":"various ","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-09T14:45:45.955007Z","id":"CVE-2021-46791","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.0.3","matchCriteriaId":"D2C9E53C-FE78-4045-9965-1F6FD1CFDD20"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:amd:milanpi:-:*:*:*:*:*:*:*","matchCriteriaId":"1F64A4AA-A66B-4B2E-B8F1-F332E3945903"}]}]}],"references":[{"url":"https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032","source":"psirt@amd.com","tags":["Vendor Advisory"]},{"url":"https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}