Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-46795


A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.


Published

2023-01-11T08:15:13.347

Last Modified

2025-04-09T15:15:45.247

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-367
  • Type: Secondary
    CWE-367

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System amd comboam4v2_pi_firmware < 1.2.0.5 Yes
Hardware amd comboam4v2_pi - No
Operating System amd renoirpi-fp6_firmware < 1.0.0.7 Yes
Hardware amd comboam4v2_pi - No
Operating System amd cezannepi-fp6_firmware < 1.0.0.6 Yes
Hardware amd cezannepi-fp6 - No

References