Vulnerabilities > AMD > Epyc 7473X Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-09 | CVE-2021-46775 | Improper Input Validation vulnerability in AMD products Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution. | 6.8 |
2023-05-09 | CVE-2022-23818 | Improper Input Validation vulnerability in AMD products Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity. | 7.5 |
2023-05-09 | CVE-2023-20520 | Out-of-bounds Write vulnerability in AMD products Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution. | 9.8 |
2023-05-09 | CVE-2023-20524 | Out-of-bounds Write vulnerability in AMD products An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity. | 7.5 |
2023-01-11 | CVE-2021-26404 | Improper Input Validation vulnerability in AMD products Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. | 5.5 |
2022-11-09 | CVE-2022-23824 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. | 5.5 |
2022-08-10 | CVE-2021-46778 | Information Exposure Through Discrepancy vulnerability in AMD products Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). | 5.6 |
2022-05-11 | CVE-2021-26339 | Unspecified vulnerability in AMD products A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. | 5.5 |
2022-05-11 | CVE-2021-26342 | Unspecified vulnerability in AMD products In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). | 3.3 |
2022-05-11 | CVE-2021-26347 | Improper Validation of Specified Quantity in Input vulnerability in AMD products Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. | 4.7 |