Home
HIGH: 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
affected
14.0.0
unaffected
Default status
affected
2.14.3
unaffected
Default status
affected
5.3
unaffected
Description
The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.
Problem types
CWE-1428 Reliance on HTTP instead of HTTPS
Product status
14.0.0
2.14.3
5.3
References
www.amd.com/...es/product-security/bulletin/amd-sb-9027.html