← Vulnerability feed

Vulnerability record · CVE-2021-46755 · published 9 May 2023

CVE-2021-46755: Amd ryzen 5500 firmware vulnerability

AAmd · Ryzen 5500 Firmware

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

7.5 CVSS 3.1 High EPSS 0.62% · top 52.3%
7.5CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
23Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-46755 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-46754Amd ryzen 5300g firmware improper input validation vulnerabilityInsufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloa…EPSS 0.57%9.1CVE-2021-46753Amd ryzen 6600h firmware vulnerabilityFailure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL …EPSS 0.56%8.8CVE-2021-46773Amd ryzen 6600h firmware improper input validation vulnerabilityInsufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code exe…EPSS 0.77%7.5CVE-2021-46794Amd ryzen 5300g firmware out-of-bounds read vulnerabilityInsufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …EPSS 0.62%7.5CVE-2021-46765Amd ryzen 6600h firmware out-of-bounds read vulnerabilityInsufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially le…EPSS 0.62%7.5CVE-2021-46749Amd ryzen 5300g firmware out-of-bounds read vulnerabilityInsufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …EPSS 0.62%6.1CVE-2021-46759Amd ryzen 5300g firmware out-of-bounds write vulnerabilityImproper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that ru…EPSS 0.28%5.9CVE-2021-46792Amd ryzen 5300g firmware toctou race condition vulnerabilityTime-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP boo…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2021-46755), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.