Vulnerabilities > AMD > Epyc 7643 Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-11-16 CVE-2021-26312 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
local
low complexity
amd CWE-668
5.5
2021-11-16 CVE-2021-26322 Use of Insufficiently Random Values vulnerability in AMD products
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
network
low complexity
amd CWE-330
7.5
2021-11-16 CVE-2021-26326 Improper Initialization vulnerability in AMD products
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
local
low complexity
amd CWE-665
7.8
2021-11-16 CVE-2021-26329 Integer Overflow or Wraparound vulnerability in AMD products
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
local
low complexity
amd CWE-190
5.5
2021-11-16 CVE-2021-26338 Unspecified vulnerability in AMD products
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
network
low complexity
amd
7.5
2021-06-11 CVE-2020-12988 Unspecified vulnerability in AMD products
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
network
low complexity
amd
7.5