Vulnerabilities > AMD > Epyc 7453 Firmware > milanpi.sp3.1.0.0.5

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2021-26356 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
network
high complexity
amd CWE-367
7.4
2023-05-09 CVE-2021-26371 Unspecified vulnerability in AMD products
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
local
low complexity
amd
5.5
2023-05-09 CVE-2021-26379 Unspecified vulnerability in AMD products
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
network
low complexity
amd
critical
9.8
2023-05-09 CVE-2021-26397 Unspecified vulnerability in AMD products
Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.
local
low complexity
amd
7.1
2023-01-11 CVE-2021-26316 Improper Input Validation vulnerability in AMD products
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
local
low complexity
amd CWE-20
7.8
2023-01-11 CVE-2021-26328 Unspecified vulnerability in AMD products
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
local
low complexity
amd
4.4
2023-01-11 CVE-2021-26343 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
local
low complexity
amd CWE-668
5.5
2023-01-11 CVE-2021-26355 Unspecified vulnerability in AMD products
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
local
low complexity
amd
5.5
2023-01-11 CVE-2021-26396 Insufficient Verification of Data Authenticity vulnerability in AMD products
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
local
low complexity
amd CWE-345
4.4
2023-01-11 CVE-2021-26398 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
local
low complexity
amd CWE-787
7.8