828
VMScore

CVE-2018-8930

Published: 22/03/2018 Updated: 24/08/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amd ryzen_mobile_firmware -

amd ryzen_pro_firmware -

amd epyc_server_firmware -

amd ryzen_firmware -

Vendor Advisories

Vulnerability Description Impact MASTERKEY Attacker who already has compromised the security of a system updates flash to corrupt its contents AMD Secure Processor (PSP) checks do not detect the corruption Requires administrative access to the targeted system Circumvention of platform security controls These changes are persistent f ...