Amd Epyc Embedded 7002 vulnerabilities
9 known vulnerabilities affecting amd/amd_epyc_embedded_7002.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-31315HIGHCVSS 7.5vvarious2024-08-12
CVE-2023-31315 [HIGH] CWE-94 CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 ac
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2022-23829HIGHCVSS 8.2vvarious2024-06-18
CVE-2022-23829 [HIGH] CWE-284 CVE-2022-23829: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kerne
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flas
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2021-46774HIGHCVSS 7.5vvarious2023-11-14
CVE-2021-46774 [HIGH] CVE-2021-46774: Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/w
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2023-20533HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20533 [HIGH] CVE-2023-20533: Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/w
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2021-26345MEDIUMCVSS 4.9vvarious2023-11-14
CVE-2021-26345 [MEDIUM] CWE-125 CVE-2021-26345: Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
cvelistv5nvd
CVE-2023-20526MEDIUMCVSS 4.6vvarious2023-11-14
CVE-2023-20526 [MEDIUM] CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical a
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
cvelistv5nvd
CVE-2023-20521MEDIUMCVSS 5.7vvarious2023-11-14
CVE-2023-20521 [MEDIUM] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
cvelistv5nvd
CVE-2021-46762CRITICALCVSS 9.1vvarious2023-05-09
CVE-2021-46762 [CRITICAL] CWE-20 CVE-2021-46762: Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leadi
Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leading to a loss of
integrity or denial of service.
cvelistv5nvd