Junglewise Threat Intelligence

CVE-2024-21950: AMD Remote Management Firmware Out-of-Bounds Read

CVE-2024-21950 · Severity: info · CVSS 1.8 · Published 2026-05-15

Vendors: Amd.

Executive brief

A security vulnerability exists in AMD's remote management firmware, which is used for out-of-band administration of server hardware. A highly privileged attacker with local access could read restricted areas of system memory, potentially leading to the exposure of sensitive information or causing minor service disruptions. This issue requires significant administrative access to exploit, limiting the overall risk to most organizations.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists within the AMD remote management firmware. The flaw is triggered when the firmware fails to properly validate memory boundaries during read operations. To exploit this, an attacker must already possess high privileges (PR:H) and local access to the system. Successful exploitation allows the attacker to read a limited section of memory outside of established bounds, which could result in the disclosure of sensitive data or a localized denial-of-service condition. The CVSS 4.0 score of 1.8 reflects the high complexity and high privilege requirements for exploitation.

Affected products

  • AMD Remote Management Firmware

Timeline

  • 2026-05-15: disclosed: Initial disclosure by AMD and NVD publication.

References