Amd 1St Gen Epyc vulnerabilities
5 known vulnerabilities affecting amd/1st_gen_epyc.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-26316HIGHCVSS 7.8vvarious 2023-01-11
CVE-2021-26316 [HIGH] CWE-20 CVE-2021-26316: Failure to validate the communication buffer and communication service in the BIOS may allow an atta
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
cvelistv5nvd
CVE-2021-26398HIGHCVSS 7.8vvarious 2023-01-11
CVE-2021-26398 [HIGH] CWE-787 CVE-2021-26398: Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
cvelistv5nvd
CVE-2021-46779HIGHCVSS 7.1vvarious 2023-01-11
CVE-2021-46779 [HIGH] CWE-787 CVE-2021-46779: Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or
Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
cvelistv5nvd
CVE-2021-26403MEDIUMCVSS 6.5vvarious 2023-01-11
CVE-2021-26403 [MEDIUM] CWE-345 CVE-2021-26403: Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potential
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
cvelistv5nvd
CVE-2023-20527MEDIUMCVSS 6.5vvarious 2023-01-11
CVE-2023-20527 [MEDIUM] CWE-20 CVE-2023-20527: Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memo
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
cvelistv5nvd