LiveActive security incident?Get immediate response
CVE Record

CVE-2021-46748: Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outsi...

Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue is in AMD’s Secure Processor handling for certain Radeon graphics products. A trusted application could be allowed to access memory outside its permitted range, which the source describes as potentially causing denial of service. The provided data does not include a CVSS score or evidence of active exploitation.

Executive priority

Address during the next normal endpoint and workstation driver maintenance cycle, escalating only for high-dependency systems. The known impact is denial of service, and the supplied sources do not show active exploitation.

Technical view

CVE-2021-46748 is described as insufficient bounds checking in the AMD Secure Processor. The impacted context is Trusted Application memory access on listed Radeon RX, Radeon PRO, Vega, and PRO WX Vega graphics products. The stated outcome is potential denial of service; confidentiality or code execution impact is not stated in the bundle.

Likely exposure

Exposure is most likely on systems running the listed AMD Radeon RX 5000/6000/7000, Radeon PRO W5000/W6000/W7000, Radeon RX Vega, or Radeon PRO WX Vega graphics products with affected AMD software or firmware baselines.

Exploitation context

The bundle marks KEV as false and provides no public exploit status, attacker prerequisites, or exploitation reports. Treat this as a vendor-advisory-driven remediation item rather than confirmed active exploitation.

Researcher notes

Evidence is limited: no CVSS vector, CWE, exploitability details, or exact vulnerable version ranges are included in the bundle. The Intel advisory is listed as a reference, but the AMD bulletin is the primary source for AMD product exposure and remediation.

Mitigation direction

  • Review AMD bulletin AMD-SB-6003 for product-specific remediation guidance.
  • Update applicable AMD Software packages where the vendor advisory identifies fixed releases.
  • Prioritize systems where GPU instability would affect production or security workloads.
  • Monitor AMD security advisories for revised severity or affected-version details.

Validation and detection

  • Inventory endpoints and workstations using the listed Radeon and Radeon PRO GPU families.
  • Record installed AMD Software package versions, including Adrenalin Edition and PRO Edition.
  • Compare installed versions against AMD bulletin AMD-SB-6003 guidance.
  • Check operational logs for unexplained GPU driver resets or denial-of-service symptoms.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-46748 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMDRadeon™ RX 5000/6000/7000 Series Graphics CardsAMD Software: Adrenalin Edition 23.7.1, variousunaffected
AMDRadeon™ PRO W5000/W6000/W7000 Series Graphics CardsAMD Software: PRO Edition 23.Q3, variousunaffected
AMDRadeon™ RX Vega Series Graphics Cardsvariousunaffected
AMDRadeon™ PRO WX Vega Series Graphics Cardsvariousunaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.