Amd Epyc Embedded 9003 vulnerabilities

6 known vulnerabilities affecting amd/amd_epyc_embedded_9003.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-21978HIGHCVSS 7.9≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2024-21978 [HIGH] CWE-20 CVE-2024-21978: Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest m Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
cvelistv5nvd
CVE-2024-21980HIGHCVSS 7.9≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2024-21980 [HIGH] CWE-119 CVE-2024-21980: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to poten Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
cvelistv5nvd
CVE-2023-31355MEDIUMCVSS 6.0≥ various, < EmbGenoaPI-SP5 1.0.0.72024-08-05
CVE-2023-31355 [MEDIUM] CWE-119 CVE-2023-31355: Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overw Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
cvelistv5nvd
CVE-2023-20587HIGHCVSS 7.1vvarious2024-02-13
CVE-2023-20587 [HIGH] CWE-284 CVE-2023-20587: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flas Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2023-20566HIGHCVSS 7.5vvarious2023-11-14
CVE-2023-20566 [HIGH] CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
cvelistv5nvd
CVE-2021-46766MEDIUMCVSS 5.5vvarious2023-11-14
CVE-2021-46766 [MEDIUM] CWE-459 CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged att Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
cvelistv5nvd