cbcvebase.
CVE-2020-12944
published 2021-11-16

CVE-2020-12944: Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
amdathlon_series
amdepyc_7232p_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7251_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7252_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7261_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7262_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7272_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7281_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7282_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_72f3_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4
amdepyc_7301_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7302_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7302p_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7313_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4
amdepyc_7313p_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4
amdepyc_7343_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4
amdepyc_7351_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7351p_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7352_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7371_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_73f3_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4
amdepyc_7401_firmware< naplespi-sp3_1.0.0.gnaplespi-sp3_1.0.0.g
amdepyc_7402_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7402p_firmware< romepi-sp3_1.0.0.cromepi-sp3_1.0.0.c
amdepyc_7413_firmware< milanpi-sp3_1.0.0.4milanpi-sp3_1.0.0.4