Vulnerabilities > AMD > Epyc 7473X Firmware > milanpi.sp3.1.0.0.7

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2021-26371 Unspecified vulnerability in AMD products
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
local
low complexity
amd
5.5
2023-05-09 CVE-2021-26379 Unspecified vulnerability in AMD products
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
network
low complexity
amd
critical
9.8
2023-05-09 CVE-2021-26397 Unspecified vulnerability in AMD products
Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.
local
low complexity
amd
7.1
2023-01-11 CVE-2021-26404 Improper Input Validation vulnerability in AMD products
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
local
low complexity
amd CWE-20
5.5