CVE-2021-26346

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

Published: 2023-01-11 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-26346 is rated Low Risk (26.1/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-26346

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.05% 0.21% +0.16%
2 2025-03-30 0.04% 0.05% +0.01%
3 2025-03-29 0.04%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-26346

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 3.6 [email protected]
5.5 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 3.6 134c704f-9b21-4f2e-91b3-4a467353bcc0

Weakness enumeration for CVE-2021-26346

OS Trackers for CVE-2021-26346

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2021-26346

Affected software / configurations for CVE-2021-26346

Vendor Product Version Raw CPE
amd ryzen_3_3100_firmware cpe:2.3:o:amd:ryzen_3_3100_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3200g_firmware cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3200u_firmware cpe:2.3:o:amd:ryzen_3_3200u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3250c_firmware cpe:2.3:o:amd:ryzen_3_3250c_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3250u_firmware cpe:2.3:o:amd:ryzen_3_3250u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3300g_firmware cpe:2.3:o:amd:ryzen_3_3300g_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3300u_firmware cpe:2.3:o:amd:ryzen_3_3300u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3300x_firmware cpe:2.3:o:amd:ryzen_3_3300x_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3350u_firmware cpe:2.3:o:amd:ryzen_3_3350u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3450u_firmware cpe:2.3:o:amd:ryzen_3_3450u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3500c_firmware cpe:2.3:o:amd:ryzen_3_3500c_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3500u_firmware cpe:2.3:o:amd:ryzen_3_3500u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3550h_firmware cpe:2.3:o:amd:ryzen_3_3550h_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3580u_firmware cpe:2.3:o:amd:ryzen_3_3580u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3700c_firmware cpe:2.3:o:amd:ryzen_3_3700c_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3700u_firmware cpe:2.3:o:amd:ryzen_3_3700u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3750h_firmware cpe:2.3:o:amd:ryzen_3_3750h_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_3780u_firmware cpe:2.3:o:amd:ryzen_3_3780u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5125c_firmware cpe:2.3:o:amd:ryzen_3_5125c_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5300g_firmware cpe:2.3:o:amd:ryzen_3_5300g_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5300ge_firmware cpe:2.3:o:amd:ryzen_3_5300ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5300u_firmware cpe:2.3:o:amd:ryzen_3_5300u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5400u_firmware cpe:2.3:o:amd:ryzen_3_5400u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5425c_firmware cpe:2.3:o:amd:ryzen_3_5425c_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_5425u_firmware cpe:2.3:o:amd:ryzen_3_5425u_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_pro_3200g_firmware cpe:2.3:o:amd:ryzen_3_pro_3200g_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_pro_3200ge_firmware cpe:2.3:o:amd:ryzen_3_pro_3200ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_3_pro_3300u_firmware cpe:2.3:o:amd:ryzen_3_pro_3300u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3400g_firmware cpe:2.3:o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3450g_firmware cpe:2.3:o:amd:ryzen_5_3450g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3450u_firmware cpe:2.3:o:amd:ryzen_5_3450u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3500_firmware cpe:2.3:o:amd:ryzen_5_3500_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3500c_firmware cpe:2.3:o:amd:ryzen_5_3500c_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3500u_firmware cpe:2.3:o:amd:ryzen_5_3500u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3500x_firmware cpe:2.3:o:amd:ryzen_5_3500x_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3550h_firmware cpe:2.3:o:amd:ryzen_5_3550h_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3580u_firmware cpe:2.3:o:amd:ryzen_5_3580u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3600_firmware cpe:2.3:o:amd:ryzen_5_3600_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3600x_firmware cpe:2.3:o:amd:ryzen_5_3600x_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_3600xt_firmware cpe:2.3:o:amd:ryzen_5_3600xt_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5500_firmware cpe:2.3:o:amd:ryzen_5_5500_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5500u_firmware cpe:2.3:o:amd:ryzen_5_5500u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5560u_firmware cpe:2.3:o:amd:ryzen_5_5560u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600_firmware cpe:2.3:o:amd:ryzen_5_5600_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600g_firmware cpe:2.3:o:amd:ryzen_5_5600g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600ge_firmware cpe:2.3:o:amd:ryzen_5_5600ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600h_firmware cpe:2.3:o:amd:ryzen_5_5600h_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600hs_firmware cpe:2.3:o:amd:ryzen_5_5600hs_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600u_firmware cpe:2.3:o:amd:ryzen_5_5600u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5600x_firmware cpe:2.3:o:amd:ryzen_5_5600x_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5625c_firmware cpe:2.3:o:amd:ryzen_5_5625c_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5625u_firmware cpe:2.3:o:amd:ryzen_5_5625u_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5700g_firmware cpe:2.3:o:amd:ryzen_5_5700g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_5700ge_firmware cpe:2.3:o:amd:ryzen_5_5700ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_pro_3350g_firmware cpe:2.3:o:amd:ryzen_5_pro_3350g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_pro_3350ge_firmware cpe:2.3:o:amd:ryzen_5_pro_3350ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_pro_3400g_firmware cpe:2.3:o:amd:ryzen_5_pro_3400g_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_pro_3400ge_firmware cpe:2.3:o:amd:ryzen_5_pro_3400ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_5_pro_3500u_firmware cpe:2.3:o:amd:ryzen_5_pro_3500u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3700c_firmware cpe:2.3:o:amd:ryzen_7_3700c_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3700u_firmware cpe:2.3:o:amd:ryzen_7_3700u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3700x_firmware cpe:2.3:o:amd:ryzen_7_3700x_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3750h_firmware cpe:2.3:o:amd:ryzen_7_3750h_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3780u_firmware cpe:2.3:o:amd:ryzen_7_3780u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3800x_firmware cpe:2.3:o:amd:ryzen_7_3800x_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_3800xt_firmware cpe:2.3:o:amd:ryzen_7_3800xt_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5700g_firmware cpe:2.3:o:amd:ryzen_7_5700g_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5700ge_firmware cpe:2.3:o:amd:ryzen_7_5700ge_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5700u_firmware cpe:2.3:o:amd:ryzen_7_5700u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5700x_firmware cpe:2.3:o:amd:ryzen_7_5700x_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800_firmware cpe:2.3:o:amd:ryzen_7_5800_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800h_firmware cpe:2.3:o:amd:ryzen_7_5800h_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800hs_firmware cpe:2.3:o:amd:ryzen_7_5800hs_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800u_firmware cpe:2.3:o:amd:ryzen_7_5800u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800x_firmware cpe:2.3:o:amd:ryzen_7_5800x_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5800x3d_firmware cpe:2.3:o:amd:ryzen_7_5800x3d_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5825c_firmware cpe:2.3:o:amd:ryzen_7_5825c_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_5825u_firmware cpe:2.3:o:amd:ryzen_7_5825u_firmware:-:*:*:*:*:*:*:*
amd ryzen_7_pro_3700u_firmware cpe:2.3:o:amd:ryzen_7_pro_3700u_firmware:-:*:*:*:*:*:*:*
amd ryzen_9_3900_firmware cpe:2.3:o:amd:ryzen_9_3900_firmware:-:*:*:*:*:*:*:*

References for CVE-2021-26346

cvelogic Threat Intelligence