(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in ASP to
extract ASP cryptographic keys, potentially resulting in loss of
confidentiality and integrity.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19587 | Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity. |
Thu, 15 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amd
Amd athlon Amd epyc Amd ryzen |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:h:amd:athlon:-:*:*:*:*:*:*:* cpe:2.3:h:amd:epyc:-:*:*:*:*:*:*:* cpe:2.3:h:amd:ryzen:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Amd
Amd athlon Amd epyc Amd ryzen |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2024-08-15T18:09:24.358Z
Reserved: 2024-01-03T16:43:30.197Z
Link: CVE-2024-21981
Updated: 2024-08-14T20:36:30.773Z
Status : Deferred
Published: 2024-08-13T17:15:22.920
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-21981
No data.
OpenCVE Enrichment
No data.
EUVD