Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2021-26409 Classic Buffer Overflow vulnerability in AMD Milanpi Firmware
Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secure Nested Paging) memory integrity.
local
low complexity
amd CWE-120
7.8
2023-01-11 CVE-2021-46779 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
local
low complexity
amd CWE-787
7.1
2023-01-11 CVE-2023-20522 Improper Input Validation vulnerability in AMD Milanpi Firmware and Romepi Firmware
Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.
network
low complexity
amd CWE-20
7.5
2023-01-11 CVE-2023-20529 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2023-01-11 CVE-2023-20530 Improper Input Validation vulnerability in AMD products
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
network
low complexity
amd CWE-20
7.5
2023-01-11 CVE-2023-20531 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
network
low complexity
amd CWE-119
7.5
2022-11-15 CVE-2022-29277 Out-of-bounds Write vulnerability in multiple products
Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses.
local
low complexity
amd intel CWE-787
8.8
2022-11-09 CVE-2020-12930 Unspecified vulnerability in AMD products
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
local
low complexity
amd
7.8
2022-11-09 CVE-2020-12931 Unspecified vulnerability in AMD products
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
local
low complexity
amd
7.8
2022-11-09 CVE-2021-26360 Unspecified vulnerability in AMD products
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers.
local
low complexity
amd
7.8