Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ryzen 3 3300 Firmware HIGH 7.8
CVE-2023-20555

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-cont…

Mitigation only
Fix from $1,950 2023-08-08
Amd Uprof HIGH 7.8
CVE-2023-20562

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver pote…

Fix: 4.1.396 / 4.1-424+
Fix from $1,950 2023-08-08
Ryzen 5 Pro 3400g Firmware MEDIUM 6.8
CVE-2023-20589

An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in …

Mitigation only
Fix from $1,600 2023-08-08
Amd Uprof MEDIUM 5.5
CVE-2023-20556

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer pot…

Fix: 4.1.396 / 4.1-424+
Fix from $1,600 2023-08-08
Amd Uprof MEDIUM 5.5
CVE-2023-20561

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address po…

Fix: 4.1.396 / 4.1-424+
Fix from $1,600 2023-08-08
Epyc 7251 Firmware MEDIUM 6.5
CVE-2023-20575

A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to m…

Mitigation only
Fix from $1,600 2023-07-11
Ryzen 3945wx Firmware CRITICAL 9.8
CVE-2021-46760

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that ma…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 5300g Firmware CRITICAL 9.1
CVE-2021-46754

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloa…

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46756

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or A…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 6600h Firmware HIGH 8.8
CVE-2021-46773

Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code exe…

No fix yet
Fix from $1,950 2023-05-09
Ryzen 5500 Firmware HIGH 7.5
CVE-2021-46755

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloade…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 6600h Firmware HIGH 7.5
CVE-2021-46765

Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially le…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware HIGH 7.5
CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware MEDIUM 6.1
CVE-2021-46759

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that ru…

Mitigation only
Fix from $1,600 2023-05-09
Ryzen 5300g Firmware MEDIUM 5.9
CVE-2021-46792

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP boo…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.8
CVE-2023-20520

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potential…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 6600h Firmware CRITICAL 9.1
CVE-2021-46753

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL …

No fix yet
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.1
CVE-2021-46762

Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

Mitigation only
Fix from $2,300 2023-05-09
Epyc 72f3 Firmware HIGH 8.8
CVE-2021-46769

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code e…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2021-46763

Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially l…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2021-46764

Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2022-23818

Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.5
CVE-2023-20524

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware MEDIUM 6.8
CVE-2021-46775

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss o…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 72f3 Firmware CRITICAL 9.8
CVE-2021-26379

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of i…

Mitigation only
Fix from $2,300 2023-05-09
Ryzen 5 2400g Firmware HIGH 8.2
CVE-2021-26365

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potenti…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 7232p Firmware HIGH 7.5
CVE-2021-26406

Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user appl…

Mitigation only
Fix from $1,950 2023-05-09
Ryzen 5300g Firmware HIGH 7.5
CVE-2021-46749

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum …

Mitigation only
Fix from $1,950 2023-05-09
Epyc 7001 Firmware HIGH 7.4
CVE-2021-26356

A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption…

Mitigation only
Fix from $1,950 2023-05-09
Epyc 72f3 Firmware HIGH 7.1
CVE-2021-26397

Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in…

No fix yet
Fix from $1,950 2023-05-09