VendorsAMDepyc_7h12_firmwareall versions
Vulnerabilities

AMD Advanced Micro Devices (AMD)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

53CVEs
CVE-2020-12966
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor.
Published 2022-02-04 · Modified
5.5EPSS 0.003
CVE-2021-26321
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
Published 2021-11-16 · Modified
5.5EPSS 0.003
CVE-2021-26312
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
Published 2021-11-16 · Modified
5.5EPSS 0.002
CVE-2021-26329
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
Published 2021-11-16 · Modified
5.5EPSS 0.002
CVE-2021-26371
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
Published 2023-05-09 · Modified
5.5EPSS 0.002
CVE-2021-26320
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
Published 2021-11-16 · Modified
5.5EPSS 0.002
CVE-2021-26354
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
Published 2023-05-09 · Modified
5.5EPSS 0.002
CVE-2023-20532
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
Published 2023-01-10 · Modified
5.3EPSS 0.006
CVE-2021-26345
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
Published 2023-11-14 · Modified
4.9EPSS 0.004
CVE-2022-27672
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
Published 2023-02-14 · Modified
4.7EPSS 0.003
CVE-2021-26347
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Published 2022-05-11 · Modified
4.7EPSS 0.002
CVE-2023-20526
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Published 2023-11-14 · Modified
4.6EPSS 0.003
CVE-2023-20528
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
Published 2023-01-10 · Modified
2.4EPSS 0.002
← Prev2 / 2