Vulnerabilities > AMD > Ryzen Threadripper PRO 3955Wx Firmware > castlepeakwspi.swrx8.1.0.0.9

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2021-46766 Incomplete Cleanup vulnerability in AMD products
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
local
low complexity
amd CWE-459
5.5
2022-05-11 CVE-2021-26373 Improper Input Validation vulnerability in AMD products
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
local
low complexity
amd CWE-20
5.5
2022-05-11 CVE-2021-26376 Unspecified vulnerability in AMD products
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
local
low complexity
amd
5.5
2022-05-11 CVE-2021-26388 Out-of-bounds Read vulnerability in AMD products
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
local
low complexity
amd CWE-125
5.5