Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Epyc 7773x Firmware MEDIUM 5.5
CVE-2021-26354

Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be…

Mitigation only
Fix from $1,600 2023-05-09
Epyc 7773x Firmware MEDIUM 5.5
CVE-2021-26371

A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, po…

Mitigation only
Fix from $1,600 2023-05-09
Ryzen 7 5700g Firmware HIGH 8.8
CVE-2023-20558

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalat…

Mitigation only
Fix from $1,950 2023-04-02
Ryzen 7 5700g Firmware HIGH 8.8
CVE-2023-20559

Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escal…

Mitigation only
Fix from $1,950 2023-04-02
Ryzen Master HIGH 7.8
CVE-2022-27677

Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading…

Fix: 2.10.1.2287+
Fix from $1,950 2023-03-01
Epyc 7h12 Firmware HIGH 7.5
CVE-2023-20531

Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a de…

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware MEDIUM 5.3
CVE-2023-20532

Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

Mitigation only
Fix from $1,600 2023-01-11
Milanpi Firmware HIGH 7.5
CVE-2023-20522

Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

Fix: 1.0.0.5 / 100d+
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware HIGH 7.5
CVE-2023-20529

Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial …

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7003 Firmware HIGH 7.5
CVE-2023-20530

Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.

Mitigation only
Fix from $1,950 2023-01-11
Romepi Firmware HIGH 7.1
CVE-2021-46779

Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Sec…

Fix: 1.0.0.c / 1.0.0.g+
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware MEDIUM 6.5
CVE-2023-20525

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register po…

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware MEDIUM 6.5
CVE-2023-20527

Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial…

Mitigation only
Fix from $1,600 2023-01-11
Romepi Firmware MEDIUM 6.1
CVE-2021-46767

Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a los…

Fix: 1.0.0.d / 1.0.0.6+
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware MEDIUM 5.7
CVE-2023-20523

TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.

Mitigation only
Fix from $1,600 2023-01-11
Romepi Firmware MEDIUM 5.5
CVE-2021-46768

Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially lea…

Fix: 1.0.0.d / 1.0.0.5+
Fix from $1,600 2023-01-11
Milanpi Firmware MEDIUM 5.5
CVE-2021-46791

Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corr…

Fix: 1.0.0.3+
Fix from $1,600 2023-01-11
Milanpi Sp3 Firmware MEDIUM 5.3
CVE-2022-23813

The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a…

Fix: 1.0.0.e / 1.0.0.9+
Fix from $1,600 2023-01-11
Milanpi Sp3 Firmware MEDIUM 5.3
CVE-2022-23814

Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential com…

Fix: 1.0.0.9+
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware HIGH 7.8
CVE-2021-26398

Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure…

Mitigation only
Fix from $1,950 2023-01-11
Milanpi Firmware HIGH 7.8
CVE-2021-26409

Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secur…

Fix: 1.0.0.3+
Fix from $1,950 2023-01-11
Epyc 7h12 Firmware HIGH 7.1
CVE-2021-26402

Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-co…

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7001 Firmware MEDIUM 6.5
CVE-2021-26403

Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26355

Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potenti…

Mitigation only
Fix from $1,600 2023-01-11
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26404

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

Mitigation only
Fix from $1,600 2023-01-11
Romepi Firmware MEDIUM 5.5
CVE-2021-26407

A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.

Fix: 1.0.0.a+
Fix from $1,600 2023-01-11
Epyc 7h12 Firmware HIGH 7.8
CVE-2021-26316

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in poten…

Mitigation only
Fix from $1,950 2023-01-11
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26343

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which …

Mitigation only
Fix from $1,600 2023-01-11
Ryzen 3 3100 Firmware MEDIUM 5.5
CVE-2021-26346

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 dir…

Mitigation only
Fix from $1,600 2023-01-11
Genoa Firmware HIGH 8.8
CVE-2022-29277

Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver,…

Fix: 05.36.10.0017 / 05.36.26.0016+
Fix from $1,950 2022-11-15