Vulnerabilities > AMD > Epyc 7313 Firmware > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-11 | CVE-2023-20575 | Information Exposure Through Discrepancy vulnerability in AMD products A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information. | 6.5 |
2023-05-09 | CVE-2021-26354 | Classic Buffer Overflow vulnerability in AMD products Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | 5.5 |
2023-05-09 | CVE-2021-26371 | Unspecified vulnerability in AMD products A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. | 5.5 |
2023-05-09 | CVE-2021-46775 | Improper Input Validation vulnerability in AMD products Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution. | 6.8 |
2023-01-11 | CVE-2021-26328 | Unspecified vulnerability in AMD products Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. | 4.4 |
2023-01-11 | CVE-2021-26343 | Exposure of Resource to Wrong Sphere vulnerability in AMD products Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. | 5.5 |
2023-01-11 | CVE-2021-26355 | Unspecified vulnerability in AMD products Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service. | 5.5 |
2023-01-11 | CVE-2021-26396 | Insufficient Verification of Data Authenticity vulnerability in AMD products Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. | 4.4 |
2023-01-11 | CVE-2021-26404 | Improper Input Validation vulnerability in AMD products Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. | 5.5 |
2023-01-11 | CVE-2023-20523 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. | 5.7 |