CVE-2024-21927: AMD Instinct MI300X

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.

Affected products

  • AMD AMD Instinct MI300X

Published 2025-09-23. Last modified 2026-06-17.