Vulnerabilities > AMD > Epyc 7351 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2021-46774 Unspecified vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
network
low complexity
amd
7.5
2023-05-09 CVE-2021-26356 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
network
high complexity
amd CWE-367
7.4
2023-05-09 CVE-2021-26406 Unspecified vulnerability in AMD products
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.
network
low complexity
amd
7.5
2023-01-11 CVE-2021-26398 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
local
low complexity
amd CWE-787
7.8
2022-05-10 CVE-2021-26408 Unspecified vulnerability in AMD products
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
local
low complexity
amd
7.1
2021-12-10 CVE-2021-26340 Unspecified vulnerability in AMD products
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
local
low complexity
amd
8.4
2021-11-16 CVE-2020-12944 Improper Input Validation vulnerability in AMD products
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
local
low complexity
amd CWE-20
7.8
2021-11-16 CVE-2020-12951 Race Condition vulnerability in AMD products
Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.
local
high complexity
amd CWE-362
7.0
2021-11-16 CVE-2021-26331 Unspecified vulnerability in AMD products
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
local
low complexity
amd
7.8
2021-11-16 CVE-2021-26335 Unspecified vulnerability in AMD products
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
local
low complexity
amd
7.8