Vulnerabilities > AMD > Epyc 73F3 Firmware > milanpi.sp3.1.0.0.5

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2023-20523 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
high complexity
amd CWE-367
5.7
2023-01-11 CVE-2023-20525 Improper Input Validation vulnerability in AMD products
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
network
low complexity
amd CWE-20
6.5
2023-01-11 CVE-2023-20527 Improper Input Validation vulnerability in AMD products
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
network
low complexity
amd CWE-20
6.5
2023-01-11 CVE-2023-20528 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
low complexity
amd CWE-20
2.4
2023-01-11 CVE-2023-20529 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2023-01-11 CVE-2023-20530 Improper Input Validation vulnerability in AMD products
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
network
low complexity
amd CWE-20
7.5
2023-01-11 CVE-2023-20531 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2023-01-11 CVE-2023-20532 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
network
low complexity
amd CWE-20
5.3
2022-05-11 CVE-2021-26339 Unspecified vulnerability in AMD products
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service.
local
low complexity
amd
5.5
2022-05-11 CVE-2021-26342 Unspecified vulnerability in AMD products
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB).
local
low complexity
amd
3.3