Vulnerabilities > AMD > Epyc 7002 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2022-29900 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
local
low complexity
xen debian fedoraproject amd CWE-212
6.5
2022-06-15 CVE-2022-23823 Information Exposure Through Discrepancy vulnerability in AMD products
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
network
low complexity
amd CWE-203
6.5
2022-05-11 CVE-2021-26347 Improper Validation of Specified Quantity in Input vulnerability in AMD products
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
local
high complexity
amd CWE-1284
4.7
2022-05-11 CVE-2021-46744 Information Exposure Through Discrepancy vulnerability in AMD products
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
local
low complexity
amd CWE-203
6.5
2022-02-04 CVE-2020-12966 Information Exposure vulnerability in AMD products
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP).
local
low complexity
amd CWE-200
5.5
2021-11-16 CVE-2020-12954 Unspecified vulnerability in AMD products
A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.
local
low complexity
amd
5.5
2021-11-16 CVE-2021-26330 Out-of-bounds Write vulnerability in AMD products
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
local
low complexity
amd CWE-787
5.5
2021-11-16 CVE-2021-26336 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.
local
low complexity
amd CWE-119
5.5
2021-11-16 CVE-2021-26337 Unspecified vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.
local
low complexity
amd
5.5