Amd 3015Ce Firmware vulnerabilities
4 known vulnerabilities affecting amd/amd_3015ce_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-20521MEDIUMCVSS 5.7fixed in pollockpi-ft5_1.0.0.42023-11-14
CVE-2023-20521 [LOW] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
nvd
CVE-2021-26365HIGHCVSS 8.2fixed in pollockpi-ft5_1.0.0.32023-05-09
CVE-2021-26365 [HIGH] CWE-125 CVE-2021-26365: Certain size values in firmware binary headers
could trigger out of bounds reads during signature va
Certain size values in firmware binary headers
could trigger out of bounds reads during signature validation, leading to
denial of service or potentially limited leakage of information about
out-of-bounds memory contents.
nvd
CVE-2021-26354MEDIUMCVSS 5.5fixed in pollockpi-ft5_1.0.0.32023-05-09
CVE-2021-26354 [MEDIUM] CWE-120 CVE-2021-26354: Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised
Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
nvd
CVE-2021-26371MEDIUMCVSS 5.5fixed in pollockpi-ft5_1.0.0.32023-05-09
CVE-2021-26371 [MEDIUM] CVE-2021-26371: A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
nvd