Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2021-26353 Improper Initialization vulnerability in AMD products
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
local
low complexity
amd CWE-665
7.8
2022-05-10 CVE-2021-46771 Unspecified vulnerability in AMD products
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
local
low complexity
amd
7.2
2022-02-04 CVE-2020-12965 Injection vulnerability in AMD products
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
network
low complexity
amd CWE-74
7.5
2021-12-10 CVE-2020-12890 Unspecified vulnerability in AMD Generic Encapsulated Software Architecture
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.
local
low complexity
amd
7.2
2021-11-16 CVE-2020-12944 Improper Input Validation vulnerability in AMD products
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
local
low complexity
amd CWE-20
7.8
2021-11-16 CVE-2021-26331 Unspecified vulnerability in AMD products
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
local
low complexity
amd
7.2
2021-11-16 CVE-2021-26335 Unspecified vulnerability in AMD products
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
local
low complexity
amd
7.2
2021-11-16 CVE-2021-26322 Use of Insufficiently Random Values vulnerability in AMD products
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
network
low complexity
amd CWE-330
7.5
2021-11-16 CVE-2021-26326 Improper Initialization vulnerability in AMD products
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
local
low complexity
amd CWE-665
7.2
2021-11-16 CVE-2021-26338 Unspecified vulnerability in AMD products
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
network
low complexity
amd
7.5