Database/Firmware, BMC & network fabric
AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003): MULTI-TENANT ISOLATION
Impact
MULTI-TENANT ISOLATION: Incomplete cleanup in the ASP exposes the platform Master Encryption Key. CVSS 1.6 is the lowest score in this database and the description is the most alarming sentence in it - the MEK is the key underneath the platform's memory encryption. Scores measure exploitability under a specific model; they do not measure what an attacker walks away with. If the MEK leaks, patching afterwards does not put it back, and the node's cryptographic identity is spent.
Who can reach it
Local, privileged, and per AMD's scoring hard to reach in practice - which is why the number is low.
What to do
Fixed in AMD PI/AGESA firmware and delivered only as an OEM SBIOS package - AMD ships the PI drop to Dell, HPE, Supermicro, Lenovo and the ODMs, who each requalify before releasing BIOS. **Budget one to six months of OEM lag**, and note that several CVEs in this batch are marked 'no fix planned' on Naples (EPYC 7001) - for those the only remediation is retiring the hardware. Applying it means cordon, drain and a full power cycle per node; there is no driver reload, no live patch and no VBIOS step. Marked 'no fix planned' on some generations. Judge this on the asset at risk rather than the score: if you offer confidential computing, an unpatched-and-unpatchable MEK exposure path is something to know about when you write the SLA, not something to leave at the bottom of a CVSS-sorted queue.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.