Amd 1St Gen Amd Epyc Processors vulnerabilities
14 known vulnerabilities affecting amd/1st_gen_amd_epyc_processors.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH6MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2023-31315HIGHCVSS 7.5≥ various, < Naples PI 1.0.0.M2024-08-12
CVE-2023-31315 [HIGH] CWE-94 CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 ac
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2022-23829HIGHCVSS 8.2vvarious2024-06-18
CVE-2022-23829 [HIGH] CWE-284 CVE-2022-23829: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kerne
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flas
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2021-46774HIGHCVSS 7.5vvarious2023-11-14
CVE-2021-46774 [HIGH] CVE-2021-46774: Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/w
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2023-20526MEDIUMCVSS 4.6vvarious2023-11-14
CVE-2023-20526 [MEDIUM] CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical a
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
cvelistv5nvd
CVE-2023-20592MEDIUMCVSS 6.5vvarious 2023-11-14
CVE-2023-20592 [MEDIUM] CVE-2023-20592: Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
cvelistv5nvd
CVE-2023-20521MEDIUMCVSS 5.7vvarious2023-11-14
CVE-2023-20521 [MEDIUM] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
cvelistv5nvd
CVE-2023-20569MEDIUMCVSS 4.7vvarious 2023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569:
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
cvelistv5nvd
CVE-2023-20575MEDIUMCVSS 6.5vvarious 2023-07-11
CVE-2023-20575 [MEDIUM] CWE-203 CVE-2023-20575:
A potential power side-channel vulnerability in some AMD processors may allow an authenticated atta
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
cvelistv5nvd
CVE-2021-46756CRITICALCVSS 9.1vvarious 2023-05-09
CVE-2021-46756 [CRITICAL] CWE-20 CVE-2021-46756: Insufficient validation of inputs in
SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader
Insufficient validation of inputs in
SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an
attacker with a malicious Uapp or ABL to send malformed or invalid syscall to
the bootloader resulting in a potential denial of service and loss of
integrity.
cvelistv5nvd
CVE-2021-26406HIGHCVSS 7.5vvarious 2023-05-09
CVE-2021-26406 [HIGH] CVE-2021-26406: Insufficient validation in parsing Owner's
Certificate Authority (OCA) certificates in SEV (AMD Secu
Insufficient validation in parsing Owner's
Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)
and SEV-ES user application can lead to a host crash potentially resulting in
denial of service.
cvelistv5nvd
CVE-2021-26356HIGHCVSS 7.4vvarious 2023-05-09
CVE-2021-26356 [HIGH] CWE-367 CVE-2021-26356: A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to m
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
cvelistv5nvd
CVE-2021-26371MEDIUMCVSS 5.5vvarious 2023-05-09
CVE-2021-26371 [MEDIUM] CVE-2021-26371: A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
cvelistv5nvd
CVE-2022-27672MEDIUMCVSS 4.7vContact your OS vendor2023-03-01
CVE-2022-27672 [MEDIUM] CVE-2022-27672: When SMT is enabled, certain AMD processors may speculatively execute instructions using a target
fr
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target
from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
cvelistv5nvd