LiveActive security incident?Get immediate response
CVE Record

CVE-2021-46769: Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbi...

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This is a high-severity AMD server firmware issue. A logged-in, privileged attacker could abuse weak input checking in the AMD Secure Processor Bootloader to trigger arbitrary DMA copies, potentially leading to code execution. The business concern is concentrated on AMD EPYC server fleets, especially where firmware ownership and patch status are unclear.

Executive priority

Treat this as a high-priority firmware exposure management item for AMD EPYC server fleets. It is not shown as actively exploited in the supplied sources, but the potential code execution impact and firmware layer location justify prompt inventory, ownership assignment, and vendor-guided remediation tracking.

Technical view

CVE-2021-46769 is insufficient syscall input validation in the ASP Bootloader. The CVE states this may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution. The CVSS 3.1 score is 8.8 with low attack complexity, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.

Likely exposure

Potential exposure is limited to environments using affected 2nd Gen AMD EPYC and 3rd Gen AMD EPYC platforms with relevant AGESA firmware. The bundle lists versions only as “various,” so exact exposure requires mapping server models, BIOS, and AGESA versions against AMD and OEM guidance.

Exploitation context

The source bundle does not show CISA KEV inclusion or cited evidence of active exploitation. The attacker prerequisite is privileged access, so this is most concerning after initial compromise, insider misuse, or weak administrative access control on affected server platforms.

Researcher notes

Evidence is sparse in the provided bundle. The root issue is ASP Bootloader syscall input validation enabling arbitrary DMA copies. The affected version detail is not granular, and no exploit details or direct patch version data are included. Avoid broad conclusions beyond AMD EPYC 2nd and 3rd Gen AGESA guidance.

Mitigation direction

  • Review AMD-SB-3001 and applicable OEM firmware guidance for affected AGESA versions.
  • Inventory EPYC server firmware before assuming systems are unaffected.
  • Restrict and monitor privileged administrative access on potentially affected servers.
  • Prioritize vendor-directed firmware remediation for internet-facing or high-value server workloads.

Validation and detection

  • Identify systems using 2nd Gen or 3rd Gen AMD EPYC processors.
  • Record server OEM model, BIOS version, and AGESA firmware details.
  • Compare collected versions against AMD-SB-3001 and OEM advisories.
  • Confirm remediation status in asset records after vendor-directed updates.
  • Monitor AMD and OEM advisories for clarification on affected version ranges.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-46769 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H2.85.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

8.8High
CVSS 3.1 vector shape for CVE-2021-46769Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMD2nd Gen AMD EPYC™AGESA, variousunaffected
AMD3rd Gen AMD EPYC™AGESA, variousunaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.