Vulnerabilities > AMD > Epyc 8024Pn Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2023-20578 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
local
high complexity
amd CWE-367
6.4
2024-02-13 CVE-2023-31346 Unspecified vulnerability in AMD products
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
local
low complexity
amd
6.0
2024-02-13 CVE-2023-31347 Unspecified vulnerability in AMD products
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
network
low complexity
amd
4.9
2023-11-14 CVE-2021-26345 Out-of-bounds Read vulnerability in AMD products
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
network
low complexity
amd CWE-125
4.9
2023-11-14 CVE-2022-23830 Unspecified vulnerability in AMD products
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
network
low complexity
amd
5.3