Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ryzen 3945wx Firmware CRITICAL 9.8
CVE-2021-46760

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that ma…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 5300g Firmware CRITICAL 9.1
CVE-2021-46754

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloa…

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46756

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or A…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 6600h Firmware HIGH 8.8
CVE-2021-46773

Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code exe…

No fix yet
Fix from $1,950 2023-05-09
Ryzen 5500 Firmware HIGH 7.5
CVE-2021-46755

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloade…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 6600h Firmware HIGH 7.5
CVE-2021-46765

Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially le…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware HIGH 7.5
CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware MEDIUM 6.1
CVE-2021-46759

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that ru…

Mitigation only
Fix from $1,600 2023-05-09
Ryzen 5300g Firmware MEDIUM 5.9
CVE-2021-46792

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP boo…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.8
CVE-2023-20520

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potential…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 6600h Firmware CRITICAL 9.1
CVE-2021-46753

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL …

No fix yet
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46762

Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware HIGH 8.8
CVE-2021-46769

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code e…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2021-46763

Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially l…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2021-46764

Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2022-23818

Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2023-20524

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware MEDIUM 6.8
CVE-2021-46775

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss o…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.8
CVE-2021-26379

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of i…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 5 2400g Firmware HIGH 8.2
CVE-2021-26365

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potenti…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 7232p Firmware HIGH 7.5
CVE-2021-26406

Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user appl…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware HIGH 7.5
CVE-2021-46749

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 7001 Firmware HIGH 7.4
CVE-2021-26356

A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.1
CVE-2021-26397

Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in…

No fix yet
Fix from $1,950 2023-05-09
Epyc 7773x Firmware MEDIUM 5.5
CVE-2021-26354

Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 7773x Firmware MEDIUM 5.5
CVE-2021-26371

A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, po…

Mitigation only
Fix from $1,600 2023-05-09
Ryzen 7 5700g Firmware HIGH 8.8
CVE-2023-20558

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalat…

Mitigation only
Fix from $1,950 2023-04-02
Ryzen 7 5700g Firmware HIGH 8.8
CVE-2023-20559

Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escal…

Mitigation only
Fix from $1,950 2023-04-02
Epyc 7h12 Firmware HIGH 7.5
CVE-2023-20531

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a de…

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware MEDIUM 5.3
CVE-2023-20532

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

Mitigation only
Fix from $1,600 2023-01-11