Vulnerabilities > AMD > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2021-26371 Unspecified vulnerability in AMD products
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
local
low complexity
amd
5.5
2023-05-09 CVE-2021-46775 Improper Input Validation vulnerability in AMD products
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.
low complexity
amd CWE-20
6.8
2023-03-01 CVE-2022-27672 Unspecified vulnerability in AMD products
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
local
high complexity
amd
4.7
2023-01-11 CVE-2021-26328 Unspecified vulnerability in AMD products
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
local
low complexity
amd
4.4
2023-01-11 CVE-2021-26343 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
local
low complexity
amd CWE-668
5.5
2023-01-11 CVE-2021-26346 Integer Overflow or Wraparound vulnerability in AMD products
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
local
low complexity
amd CWE-190
5.5
2023-01-11 CVE-2021-26355 Unspecified vulnerability in AMD products
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
local
low complexity
amd
5.5
2023-01-11 CVE-2021-26396 Insufficient Verification of Data Authenticity vulnerability in AMD products
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
local
low complexity
amd CWE-345
4.4
2023-01-11 CVE-2021-26403 Unspecified vulnerability in AMD products
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
local
low complexity
amd
6.5
2023-01-11 CVE-2021-26404 Improper Input Validation vulnerability in AMD products
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
local
low complexity
amd CWE-20
5.5