CVE-2024-21927: AMD Instinct MI300X
Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.
Affected products
- AMD AMD Instinct MI300X
Published 2025-09-23. Last modified 2026-06-17.