Amd Epyc Embedded 9003 vulnerabilities
6 known vulnerabilities affecting amd/amd_epyc_embedded_9003.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-21978HIGHCVSS 7.9≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2024-21978 [HIGH] CWE-20 CVE-2024-21978: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest m
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
cvelistv5nvd
CVE-2024-21980HIGHCVSS 7.9≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2024-21980 [HIGH] CWE-119 CVE-2024-21980: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to poten
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
cvelistv5nvd
CVE-2023-31355MEDIUMCVSS 6.0≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2023-31355 [MEDIUM] CWE-119 CVE-2023-31355: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overw
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flas
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2023-20566HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20566 [HIGH] CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
cvelistv5nvd
CVE-2021-46766MEDIUMCVSS 5.5vvarious2023-11-14
CVE-2021-46766 [MEDIUM] CWE-459 CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged att
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
cvelistv5nvd