Vulnerabilities > AMD > Epyc 7443P Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2023-20591 Improper Initialization vulnerability in AMD products
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
network
low complexity
amd CWE-665
critical
10.0
2023-05-09 CVE-2021-46756 Improper Input Validation vulnerability in AMD products
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.
network
low complexity
amd CWE-20
critical
9.1
2023-05-09 CVE-2023-20520 Out-of-bounds Write vulnerability in AMD products
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
network
low complexity
amd CWE-787
critical
9.8
2023-05-09 CVE-2021-46762 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
network
low complexity
amd CWE-20
critical
9.1
2023-05-09 CVE-2021-26379 Unspecified vulnerability in AMD products
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
network
low complexity
amd
critical
9.8