VendorsAMDryzen_7_5700any version
Vulnerabilities

AMD Advanced Micro Devices (AMD) Ryzen 7 5700 - any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-23821
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Published 2023-11-14 · Modified
9.8EPSS 0.010
CVE-2022-23820
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Published 2023-11-14 · Modified
9.8EPSS 0.007
CVE-2023-39281
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.
Published 2023-11-01 · Modified
9.8EPSS 0.005
CVE-2023-20571
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.
Published 2023-11-14 · Modified
8.1EPSS 0.004
CVE-2023-20555
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
Published 2023-08-08 · Modified
7.8EPSS 0.003
CVE-2023-20565
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
7.8EPSS 0.002
CVE-2023-20563
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
7.8EPSS 0.002
CVE-2023-20589
fTPM Voltage Fault Injection
Published 2023-08-08 · Modified
6.8EPSS 0.006
CVE-2023-20569
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Published 2023-08-08 · Modified
4.7EPSS 0.073