Vulnerabilities > AMD > Epyc 73F3 Firmware > milanpi.1.0.0.b

DATE CVE VULNERABILITY TITLE RISK
2024-08-05 CVE-2023-31355 Out-of-bounds Write vulnerability in AMD products
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
local
low complexity
amd CWE-787
6.0
2024-08-05 CVE-2024-21978 Unspecified vulnerability in AMD products
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
local
low complexity
amd
7.9
2024-08-05 CVE-2024-21980 Out-of-bounds Write vulnerability in AMD products
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
local
low complexity
amd CWE-787
7.9
2024-02-13 CVE-2023-31346 Unspecified vulnerability in AMD products
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
local
low complexity
amd
6.0
2024-02-13 CVE-2023-31347 Unspecified vulnerability in AMD products
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
network
low complexity
amd
4.9
2023-11-14 CVE-2023-20592 Unspecified vulnerability in AMD products
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
network
low complexity
amd
6.5
2023-08-08 CVE-2023-20569 Information Exposure Through Discrepancy vulnerability in multiple products
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction.
local
high complexity
fedoraproject debian amd microsoft CWE-203
4.7