Amd 3Rd Gen Epyc vulnerabilities
26 known vulnerabilities affecting amd/3rd_gen_epyc.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2021-46768P4MEDIUMCVSS 5.5vvarious 2023-01-11
CVE-2021-46768 [MEDIUM] CWE-125 CVE-2021-46768: Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory
Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
nvd
CVE-2023-20523P4MEDIUMCVSS 5.7vvarious 2023-01-11
CVE-2023-20523 [MEDIUM] CWE-367 CVE-2023-20523: TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leadi
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
nvd
CVE-2021-26355P4MEDIUMCVSS 5.5vvarious 2023-01-11
CVE-2021-26355 [MEDIUM] CWE-693 CVE-2021-26355: Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid mess
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
nvd
CVE-2021-26396P4MEDIUMCVSS 4.4vvarious 2023-01-11
CVE-2021-26396 [MEDIUM] CWE-345 CVE-2021-26396: Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
nvd
CVE-2021-26328P4MEDIUMCVSS 4.4vvarious 2023-01-11
CVE-2021-26328 [MEDIUM] CWE-358 CVE-2021-26328: Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
nvd
CVE-2023-20528P4LOWCVSS 2.4vvarious 2023-01-11
CVE-2023-20528 [LOW] CWE-20 CVE-2023-20528: Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory cont
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
nvd
← Previous2 / 2