VendorsAMDepyc_7473x_firmwareany version
Vulnerabilities

AMD Advanced Micro Devices (AMD) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2021-26347
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Published 2022-05-11 · Modified
4.7EPSS 0.002
CVE-2021-26350
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
Published 2022-05-11 · Modified
4.7EPSS 0.001
CVE-2023-20526
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Published 2023-11-14 · Modified
4.6EPSS 0.003
CVE-2021-26342
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.
Published 2022-05-11 · Modified
3.3EPSS 0.002
CVE-2023-20573
Debug Exception Delivery in Secure Nested Paging
Published 2024-01-11 · Modified
3.2EPSS 0.003
← Prev2 / 2