VendorsAMDryzen_7_6800hs_firmwareall versions
Vulnerabilities

AMD Advanced Micro Devices (AMD) Ryzen 7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2023-20596
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.
Published 2023-11-14 · Modified
9.8EPSS 0.010
CVE-2022-23821
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Published 2023-11-14 · Modified
9.8EPSS 0.010
CVE-2022-23820
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Published 2023-11-14 · Modified
9.8EPSS 0.007
CVE-2021-26365
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
Published 2023-05-09 · Modified
8.2EPSS 0.006
CVE-2023-20571
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.
Published 2023-11-14 · Modified
8.1EPSS 0.004
CVE-2023-20555
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
Published 2023-08-08 · Modified
7.8EPSS 0.003
CVE-2023-20565
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
7.8EPSS 0.002
CVE-2023-20563
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
7.8EPSS 0.002
CVE-2023-20589
fTPM Voltage Fault Injection
Published 2023-08-08 · Modified
6.8EPSS 0.006
CVE-2023-4969
GPU kernel implementations susceptible to memory leak
Published 2024-01-16 · Modified
6.5EPSS 0.012
CVE-2021-46758
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.
Published 2023-11-14 · Modified
6.1EPSS 0.003
CVE-2023-20579
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
Published 2024-02-13 · Modified
6.0EPSS 0.002
CVE-2023-20569
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Published 2023-08-08 · Modified
4.7EPSS 0.073