Vulnerabilities > AMD > Ryzen 5 PRO 2500U Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-01-11 CVE-2021-26316 Improper Input Validation vulnerability in AMD products
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
local
low complexity
amd CWE-20
7.8
2022-05-11 CVE-2021-26339 Unspecified vulnerability in AMD products
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service.
local
low complexity
amd
5.5
2022-03-11 CVE-2021-26341 Improper Cross-boundary Removal of Sensitive Data vulnerability in AMD products
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
local
low complexity
amd CWE-212
6.5
2022-03-11 CVE-2021-26401 Unspecified vulnerability in AMD products
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
local
high complexity
amd
5.6