Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Epyc 7763 Firmware HIGH 7.8
CVE-2021-46771

Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a comprom…

Mitigation only
Fix from $1,950 2022-05-10
Epyc 7763 Firmware HIGH 7.8
CVE-2021-26353

Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potential…

Mitigation only
Fix from $1,950 2022-05-10
Epyc 7763 Firmware HIGH 7.1
CVE-2021-26332

Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

Mitigation only
Fix from $1,950 2022-05-10
Epyc 7763 Firmware HIGH 7.1
CVE-2021-26370

Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an att…

Mitigation only
Fix from $1,950 2022-05-10
Epyc 7002 Firmware HIGH 7.1
CVE-2021-26408

Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of gu…

Mitigation only
Fix from $1,950 2022-05-10
Ryzen 5 2600 Firmware MEDIUM 6.2
CVE-2021-26390

A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

No fix yet
Fix from $1,600 2022-05-10
Ryzen 5 2600 Firmware MEDIUM 5.5
CVE-2021-26352

Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could r…

Mitigation only
Fix from $1,600 2022-05-10
Epyc 7763 Firmware HIGH 7.8
CVE-2021-26324

A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.

Mitigation only
Fix from $1,950 2022-05-10
Athlon X4 940 Firmware MEDIUM 5.6
CVE-2021-26401

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

Mitigation only
Fix from $1,600 2022-03-11
Athlon X4 940 Firmware MEDIUM 6.5
CVE-2021-26341

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

Mitigation only
Fix from $1,600 2022-03-11
Xilinx Z 7012s Firmware MEDIUM 6.8
CVE-2021-44850

On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's bo…

Mitigation only
Fix from $1,600 2022-02-10
Radeon Pro Software HIGH 7.8
CVE-2020-12891

AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any …

Fix: 21.q2 / 21.4.1+
Fix from $1,950 2022-02-04
Ryzen Pro 5650g Firmware HIGH 7.5
CVE-2020-12965

When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits p…

Mitigation only
Fix from $1,950 2022-02-04
Epyc 7763 Firmware MEDIUM 5.5
CVE-2020-12966

AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure …

Mitigation only
Fix from $1,600 2022-02-04
Epyc 7001 Firmware HIGH 8.4
CVE-2021-26340

A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside…

Mitigation only
Fix from $1,950 2021-12-10
Amd Generic Encapsulated Software Architecture MEDIUM 6.7
CVE-2020-12890

Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative a…

Mitigation only
Fix from $1,600 2021-12-10
Amd Uprof CRITICAL 9.9
CVE-2021-26334

The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation an…

Fix: 3.4.494 / 3.4.502+
Fix from $2,300 2021-12-01
Epyc 7003 Firmware HIGH 7.8
CVE-2021-26331

AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary cod…

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware HIGH 7.8
CVE-2021-26335

Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values …

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26330

AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

Mitigation only
Fix from $1,600 2021-11-16
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26336

Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent f…

Mitigation only
Fix from $1,600 2021-11-16
Epyc 7003 Firmware MEDIUM 5.5
CVE-2021-26337

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not …

Mitigation only
Fix from $1,600 2021-11-16
Epyc 7601 Firmware HIGH 7.8
CVE-2020-12944

Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware HIGH 7.8
CVE-2020-12961

A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Ma…

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware HIGH 7.8
CVE-2021-26315

When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verifica…

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7232p Firmware HIGH 7.8
CVE-2021-26323

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7f72 Firmware HIGH 7.1
CVE-2020-12946

Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware HIGH 7.0
CVE-2020-12951

Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.

Mitigation only
Fix from $1,950 2021-11-16
Epyc 7003 Firmware MEDIUM 5.5
CVE-2020-12954

A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modi…

No fix yet
Fix from $1,600 2021-11-16
Epyc 7601 Firmware MEDIUM 5.5
CVE-2021-26320

Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to pe…

Mitigation only
Fix from $1,600 2021-11-16