CVE-2024-21944
Ungültige Eingabeverarbeitung für die SPD-Metadaten (Serial Presence Detect) eines DIMMs könnte es einem Angreifer mit physischem Zugriff…
mediumEPSS 0.2%
Description
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.
Source: NVD (NIST)cvelistv5
Metrics
Show all metrics
Severity
medium
47.41
no public PoC known
5.3
Published
2026-06-10 21:54 UTC
CWE-20
Weakness classes (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Translated2026-07-23 09:10 UTC· nvd@nist.gov
- Translation: Title: algunos productos de la familia EPYC de AMD, Description: La validación de entrada incorrecta para los metadatos de detección de presencia serie (SPD) de DIMM podría permitir a un atacante con acceso físico, acceso ring0 en un sistema con un DIMM no conforme, o control sobre la Raíz de Confianza para la actualización del BIOS, sobrescribir potencialmente la memoria invitada, resultando en la pérdida de integridad de los datos invitados.
- New CVE Received2026-06-10 23:16 UTC· psirt@amd.com
- Description: Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.
- CVSS V3.1: AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
- CWE: CWE-20
- Reference: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3015.html