VendorsAMDepyc_7543p_firmwareall versions
Vulnerabilities

AMD Advanced Micro Devices (AMD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2021-26355
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
Published 2023-01-10 · Modified
5.5EPSS 0.002
CVE-2023-20532
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
Published 2023-01-10 · Modified
5.3EPSS 0.006
CVE-2022-23830
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
Published 2023-11-14 · Modified
5.3EPSS 0.003
CVE-2023-31347
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.  
Published 2024-02-13 · Modified
4.9EPSS 0.005
CVE-2021-26345
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
Published 2023-11-14 · Modified
4.9EPSS 0.004
CVE-2023-20569
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Published 2023-08-08 · Modified
4.7EPSS 0.073
CVE-2021-26347
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Published 2022-05-11 · Modified
4.7EPSS 0.002
CVE-2021-26350
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
Published 2022-05-11 · Modified
4.7EPSS 0.001
CVE-2023-20526
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Published 2023-11-14 · Modified
4.6EPSS 0.003
CVE-2023-20594
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Published 2023-09-20 · Modified
4.4EPSS 0.002
CVE-2021-26328
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
Published 2023-01-10 · Modified
4.4EPSS 0.002
CVE-2021-26396
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
Published 2023-01-10 · Modified
4.4EPSS 0.001
CVE-2021-26342
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.
Published 2022-05-11 · Modified
3.3EPSS 0.002
CVE-2023-20573
Debug Exception Delivery in Secure Nested Paging
Published 2024-01-11 · Modified
3.2EPSS 0.003
CVE-2023-20528
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
Published 2023-01-10 · Modified
2.4EPSS 0.002
← Prev3 / 3