Vulnerabilities > AMD > Ryzen 3 5400U Firmware > cezannepi.fp6.1.0.0.b

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2021-46758 Unspecified vulnerability in AMD products
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.
low complexity
amd
6.1
2023-11-14 CVE-2022-23820 Improper Input Validation vulnerability in AMD products
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
network
low complexity
amd CWE-20
critical
9.8
2023-11-14 CVE-2022-23821 Unspecified vulnerability in AMD products
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
network
low complexity
amd
critical
9.8
2023-11-14 CVE-2023-20563 Improper Privilege Management vulnerability in AMD products
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
local
low complexity
amd CWE-269
7.8
2023-11-14 CVE-2023-20565 Improper Privilege Management vulnerability in AMD products
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
local
low complexity
amd CWE-269
7.8
2023-08-08 CVE-2023-20569 Information Exposure Through Discrepancy vulnerability in multiple products
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction.
local
high complexity
fedoraproject debian amd microsoft CWE-203
4.7