Amd Epyc Embedded 7003 vulnerabilities

15 known vulnerabilities affecting amd/amd_epyc_embedded_7003.

Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH8MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2023-31315HIGHCVSS 7.5vvarious2024-08-12
CVE-2023-31315 [HIGH] CWE-94 CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 ac Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2024-21978HIGHCVSS 7.9≥ various, < EmbMilanPI-SP3 1.0.0.92024-08-05
CVE-2024-21978 [HIGH] CWE-20 CVE-2024-21978: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest m Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
cvelistv5nvd
CVE-2024-21980HIGHCVSS 7.9≥ various, < EmbMilanPI-SP3 1.0.0.92024-08-05
CVE-2024-21980 [HIGH] CWE-119 CVE-2024-21980: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to poten Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
cvelistv5nvd
CVE-2023-31355MEDIUMCVSS 6.0≥ various, < EmbMilanPI-SP3 1.0.0.92024-08-05
CVE-2023-31355 [MEDIUM] CWE-119 CVE-2023-31355: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overw Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
cvelistv5nvd
CVE-2022-23829HIGHCVSS 8.2vvarious2024-06-18
CVE-2022-23829 [HIGH] CWE-284 CVE-2022-23829: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kerne A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flas Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2022-23820CRITICALCVSS 9.8vvarious2023-11-14
CVE-2022-23820 [CRITICAL] CWE-20 CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM pote Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2021-46774HIGHCVSS 7.5vvarious2023-11-14
CVE-2021-46774 [HIGH] CVE-2021-46774: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/w Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2023-20533HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20533 [HIGH] CVE-2023-20533: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/w Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
cvelistv5nvd
CVE-2023-20566HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20566 [HIGH] CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
cvelistv5nvd
CVE-2021-26345MEDIUMCVSS 4.9vvarious2023-11-14
CVE-2021-26345 [MEDIUM] CWE-125 CVE-2021-26345: Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
cvelistv5nvd
CVE-2022-23830MEDIUMCVSS 5.3vvarious2023-11-14
CVE-2022-23830 [MEDIUM] CVE-2022-23830: SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential li SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
cvelistv5nvd
CVE-2023-20526MEDIUMCVSS 4.6vvarious2023-11-14
CVE-2023-20526 [MEDIUM] CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical a Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
cvelistv5nvd
CVE-2023-20521MEDIUMCVSS 5.7vvarious2023-11-14
CVE-2023-20521 [MEDIUM] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
cvelistv5nvd
CVE-2021-46762CRITICALCVSS 9.1vvarious2023-05-09
CVE-2021-46762 [CRITICAL] CWE-20 CVE-2021-46762: Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leadi Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
cvelistv5nvd