Vulnerabilities > AMD

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2023-20525 Improper Input Validation vulnerability in AMD products
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
network
low complexity
amd CWE-20
6.5
2023-01-11 CVE-2023-20527 Improper Input Validation vulnerability in AMD products
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
network
low complexity
amd CWE-20
6.5
2023-01-11 CVE-2023-20528 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
low complexity
amd CWE-20
2.4
2023-01-11 CVE-2023-20529 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2023-01-11 CVE-2023-20530 Improper Input Validation vulnerability in AMD products
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
network
low complexity
amd CWE-20
7.5
2023-01-11 CVE-2023-20531 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2023-01-11 CVE-2023-20532 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
network
low complexity
amd CWE-20
5.3
2022-11-15 CVE-2022-29277 Out-of-bounds Write vulnerability in multiple products
Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses.
local
low complexity
amd intel CWE-787
8.8
2022-11-09 CVE-2020-12930 Unspecified vulnerability in AMD products
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
local
low complexity
amd
7.8
2022-11-09 CVE-2020-12931 Unspecified vulnerability in AMD products
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
local
low complexity
amd
7.8