Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2021-26406 Unspecified vulnerability in AMD products
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.
network
low complexity
amd
7.5
2023-05-09 CVE-2021-46749 Out-of-bounds Read vulnerability in AMD products
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.
network
low complexity
amd CWE-125
7.5
2023-05-09 CVE-2021-46763 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.
network
low complexity
amd CWE-787
7.5
2023-05-09 CVE-2021-46764 Out-of-bounds Write vulnerability in AMD products
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
network
low complexity
amd CWE-787
7.5
2023-05-09 CVE-2021-46769 Improper Input Validation vulnerability in AMD products
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
network
low complexity
amd CWE-20
8.8
2023-05-09 CVE-2022-23818 Improper Input Validation vulnerability in AMD products
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.
network
low complexity
amd CWE-20
7.5
2023-05-09 CVE-2023-20524 Out-of-bounds Write vulnerability in AMD products
An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.
network
low complexity
amd CWE-787
7.5
2023-04-02 CVE-2023-20558 Unspecified vulnerability in AMD products
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
network
low complexity
amd
8.8
2023-04-02 CVE-2023-20559 Unspecified vulnerability in AMD products
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
network
low complexity
amd
8.8
2023-03-01 CVE-2022-27677 Improper Privilege Management vulnerability in AMD Ryzen Master 2.2.0.1543
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.
local
low complexity
amd CWE-269
7.8