CVE-2024-21944

Ungültige Eingabeverarbeitung für die SPD-Metadaten (Serial Presence Detect) eines DIMMs könnte es einem Angreifer mit physischem Zugriff…

mediumEPSS 0.2%

Description

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.

Metrics

5.3
Source: nvd-v3
11.8 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-06-10 21:54 UTC
CWE-20

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-23 09:10 UTC· nvd@nist.gov
    • Translation: Title: algunos productos de la familia EPYC de AMD, Description: La validación de entrada incorrecta para los metadatos de detección de presencia serie (SPD) de DIMM podría permitir a un atacante con acceso físico, acceso ring0 en un sistema con un DIMM no conforme, o control sobre la Raíz de Confianza para la actualización del BIOS, sobrescribir potencialmente la memoria invitada, resultando en la pérdida de integridad de los datos invitados.
  2. New CVE Received2026-06-10 23:16 UTC· psirt@amd.com
    • Description: Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.
    • CVSS V3.1: AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
    • CWE: CWE-20
    • Reference: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html

Linked advisories