Amd Ryzen Embedded R2000 vulnerabilities

11 known vulnerabilities affecting amd/amd_ryzen_embedded_r2000.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-0179HIGHCVSS 8.2vEmbeddedR2KPIFP5 1.0.0.52025-02-11
CVE-2024-0179 [HIGH] CWE-20 CVE-2024-0179: SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticate SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
cvelistv5nvd
CVE-2023-31343HIGHCVSS 7.5v"EmbeddedR2KPI-FP5 1.0.0.3"2025-02-11
CVE-2023-31343 [HIGH] CWE-1220 CVE-2023-31343: Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, pot Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2023-31315HIGHCVSS 7.5vvarious2024-08-12
CVE-2023-31315 [HIGH] CWE-94 CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 ac Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2022-23821CRITICALCVSS 9.8vvarious 2023-11-14
CVE-2022-23821 [CRITICAL] CVE-2022-23821: Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM po Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
cvelistv5nvd
CVE-2023-20563HIGHCVSS 7.8vvarious 2023-11-14
CVE-2023-20563 [HIGH] CWE-269 CVE-2023-20563: Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially e Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
cvelistv5nvd
CVE-2023-20521MEDIUMCVSS 5.7vvarious2023-11-14
CVE-2023-20521 [MEDIUM] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
cvelistv5nvd
CVE-2021-46754CRITICALCVSS 9.1vvarious2023-05-09
CVE-2021-46754 [CRITICAL] CWE-20 CVE-2021-46754: Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker wit Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.
cvelistv5nvd
CVE-2020-12931HIGHCVSS 7.8vvarious2022-11-09
CVE-2020-12931 [HIGH] CVE-2020-12931: Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacke Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
cvelistv5nvd
CVE-2020-12930HIGHCVSS 7.8vvarious2022-11-09
CVE-2020-12930 [HIGH] CVE-2020-12930: Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker t Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
cvelistv5nvd
CVE-2021-26392HIGHCVSS 7.8vvarious2022-11-09
CVE-2021-26392 [HIGH] CWE-787 CVE-2021-26392: Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write p Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.
cvelistv5nvd
CVE-2021-26393MEDIUMCVSS 5.5vvarious2022-11-09
CVE-2021-26393 [MEDIUM] CWE-401 CVE-2021-26393: Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) ma Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
cvelistv5nvd