Vulnerabilities > AMD > Epyc 7443 Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-05-11 CVE-2021-26348 Unspecified vulnerability in AMD products
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
local
low complexity
amd
5.5
2022-05-11 CVE-2021-26349 Unspecified vulnerability in AMD products
Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).
local
low complexity
amd
5.5
2022-05-11 CVE-2021-46744 Information Exposure Through Discrepancy vulnerability in AMD products
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
local
low complexity
amd CWE-203
6.5
2022-05-10 CVE-2021-26324 Unspecified vulnerability in AMD products
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
local
low complexity
amd
7.8
2022-05-10 CVE-2021-26332 Unspecified vulnerability in AMD products
Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.
local
low complexity
amd
7.1
2022-05-10 CVE-2021-26353 Improper Initialization vulnerability in AMD products
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
local
low complexity
amd CWE-665
7.8
2022-05-10 CVE-2021-26370 Improper Input Validation vulnerability in AMD products
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
local
low complexity
amd CWE-20
7.1
2022-05-10 CVE-2021-46771 Unspecified vulnerability in AMD products
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
local
low complexity
amd
7.8
2022-02-04 CVE-2020-12966 Information Exposure vulnerability in AMD products
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP).
local
low complexity
amd CWE-200
5.5
2021-12-10 CVE-2021-26340 Unspecified vulnerability in AMD products
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
local
low complexity
amd
8.4