Vulnerabilities > AMD > Ryzen Threadripper 3970X Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-06-15 CVE-2022-23823 Information Exposure Through Discrepancy vulnerability in AMD products
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
network
low complexity
amd CWE-203
4.0
2022-05-12 CVE-2021-26317 Unspecified vulnerability in AMD products
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
local
low complexity
amd
7.8
2022-05-12 CVE-2021-26368 Insufficient Verification of Data Authenticity vulnerability in AMD products
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.
local
low complexity
amd CWE-345
4.9
2022-05-12 CVE-2021-26386 Out-of-bounds Write vulnerability in AMD products
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.
local
low complexity
amd CWE-787
7.8
2022-05-12 CVE-2021-26351 Improper Input Validation vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.
local
low complexity
amd CWE-20
5.5
2022-05-12 CVE-2021-26366 Unspecified vulnerability in AMD products
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
local
low complexity
amd
7.1
2022-05-11 CVE-2021-26373 Improper Input Validation vulnerability in AMD products
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
local
low complexity
amd CWE-20
5.5
2022-05-11 CVE-2021-26375 Unspecified vulnerability in AMD products
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.
local
low complexity
amd
4.9
2022-05-11 CVE-2021-26376 Unspecified vulnerability in AMD products
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
local
low complexity
amd
5.5
2022-05-11 CVE-2021-26378 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in AMD products
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
local
low complexity
amd CWE-119
4.9