Amd 3Rd Gen Amd Epyc Processors vulnerabilities
26 known vulnerabilities affecting amd/3rd_gen_amd_epyc_processors.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH9MEDIUM13LOW2
Vulnerabilities
Page 2 of 2
CVE-2023-20521P4MEDIUMCVSS 5.7vvarious2023-11-14
CVE-2023-20521 [MEDIUM] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
nvd
CVE-2021-26345P4MEDIUMCVSS 4.9vvarious2023-11-14
CVE-2021-26345 [MEDIUM] CWE-125 CVE-2021-26345: Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
nvd
CVE-2023-20526P4MEDIUMCVSS 4.6vvarious2023-11-14
CVE-2023-20526 [MEDIUM] CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical a
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
nvd
CVE-2023-20594P4MEDIUMCVSS 4.4vvarious2023-09-20
CVE-2023-20594 [MEDIUM] CWE-824 CVE-2023-20594: Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
nvd
CVE-2023-20519P4LOWCVSS 3.3vvarious 2023-11-14
CVE-2023-20519 [LOW] CWE-416 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
nvd
CVE-2023-20573P4LOWCVSS 3.2vvarious 2024-01-11
CVE-2023-20573 [LOW] CWE-693 CVE-2023-20573: A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulti
A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially
resulting in guests not receiving expected debug information.
nvd
← Previous2 / 2