The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.
History

Fri, 12 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Title Insecure HTTP Transport in AMD Optional Tools Enables MITM and Arbitrary Code Execution

Fri, 12 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.
Weaknesses CWE-1428
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2026-06-12T15:57:12.696Z

Reserved: 2026-04-14T17:04:42.500Z

Link: CVE-2026-40677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-12T16:16:27.400

Modified: 2026-06-12T16:22:46.947

Link: CVE-2026-40677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T16:30:14Z