Back to Labs
Security Advisory

CVE-2021-26315

About

When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

Weakness (CWE):CWE-345

Rainforest analyst review

Deep in the boot chain, AMD's Platform Security Processor insufficiently verifies the integrity of a decrypted firmware image, so when encrypted firmware is used, arbitrary code can end up executing within the PSP itself. This is a local bug requiring some privilege, targeting the hardware root of trust rather than the operating system above it.

An attack at this layer is inherently sophisticated and gated, it needs local privileged access and the specific encrypted-firmware condition, which puts it well outside mass exploitation and into the realm of targeted or supply-chain-minded actors. The payoff is deep and stealthy, but the barrier to reaching it is correspondingly high.

We rank this down for remote-exposure prioritization and treat it as a firmware and supply-chain inventory matter across the affected EPYC and Ryzen parts. It belongs in a specialized firmware-update track, weighed by the sensitivity of the systems involved, not in the general remote-patch queue.

References

Related CVEs

Frequently asked questions

What is CVE-2021-26315?

When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

How severe is CVE-2021-26315?

CVE-2021-26315 carries a CVSS 3.1 base score of 7.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 73 out of 100, in the high band.

How is CVE-2021-26315 exploited?

According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Local, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2021-26315?

Public advisories list the following as affected: epyc 7003, epyc 7003 firmware, epyc 72f3, epyc 72f3 firmware, epyc 7313, epyc 7313 firmware, +34. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2021-26315?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email