9
CVSSv3

CVE-2018-8933

Published: 22/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

amd epyc_server_firmware -

Vendor Advisories

Vulnerability Description Impact MASTERKEY Attacker who already has compromised the security of a system updates flash to corrupt its contents AMD Secure Processor (PSP) checks do not detect the corruption Requires administrative access to the targeted system Circumvention of platform security controls These changes are persistent f ...