Amd 4Th Gen Amd Epyc Processors vulnerabilities

14 known vulnerabilities affecting amd/4th_gen_amd_epyc_processors.

Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM7LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-21978HIGHCVSS 7.9≥ various, < GenoaPI 1.0.0.C2024-08-05
CVE-2024-21978 [HIGH] CWE-20 CVE-2024-21978: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest m Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
cvelistv5nvd
CVE-2024-21980HIGHCVSS 7.9≥ various, < GenoaPI 1.0.0.C2024-08-05
CVE-2024-21980 [HIGH] CWE-119 CVE-2024-21980: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to poten Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
cvelistv5nvd
CVE-2023-31355MEDIUMCVSS 6.0≥ various, < GenoaPI 1.0.0.C2024-08-05
CVE-2023-31355 [MEDIUM] CWE-119 CVE-2023-31355: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overw Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flas Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2023-31346MEDIUMCVSS 6.0vvarious 2024-02-13
CVE-2023-31346 [MEDIUM] CWE-284 CVE-2023-31346: Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data fr Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
cvelistv5nvd
CVE-2023-31347MEDIUMCVSS 4.9vvarious 2024-02-13
CVE-2023-31347 [MEDIUM] CWE-682 CVE-2023-31347: Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
cvelistv5nvd
CVE-2023-20573LOWCVSS 3.2vVarious 2024-01-11
CVE-2023-20573 [LOW] CWE-693 CVE-2023-20573: A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulti A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.
cvelistv5nvd
CVE-2021-46774HIGHCVSS 7.5vvarious2023-11-14
CVE-2021-46774 [HIGH] CVE-2021-46774: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/w Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2023-20566HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20566 [HIGH] CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
cvelistv5nvd
CVE-2021-46766MEDIUMCVSS 5.5vvarious2023-11-14
CVE-2021-46766 [MEDIUM] CWE-459 CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged att Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
cvelistv5nvd
CVE-2021-26345MEDIUMCVSS 4.9vvarious2023-11-14
CVE-2021-26345 [MEDIUM] CWE-125 CVE-2021-26345: Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
cvelistv5nvd
CVE-2023-20519LOWCVSS 3.3vvarious 2023-11-14
CVE-2023-20519 [LOW] CWE-416 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
cvelistv5nvd
CVE-2023-20569MEDIUMCVSS 4.7vvarious 2023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
cvelistv5nvd
CVE-2023-20575MEDIUMCVSS 6.5vVarious 2023-07-11
CVE-2023-20575 [MEDIUM] CWE-203 CVE-2023-20575: A potential power side-channel vulnerability in some AMD processors may allow an authenticated atta A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
cvelistv5nvd