Amd Epyc 7002 Firmware vulnerabilities

26 known vulnerabilities affecting amd/epyc_7002_firmware.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM12LOW1

Vulnerabilities

Page 2 of 2
CVE-2020-12951HIGHCVSS 7.0fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2020-12951 [HIGH] CWE-362 CVE-2020-12951: Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Manag Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.
nvd
CVE-2020-12954MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2020-12954 [MEDIUM] CWE-693 CVE-2020-12954: A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI RO A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.
nvd
CVE-2021-26337MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26337 [MEDIUM] CVE-2021-26337: Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from i Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.
nvd
CVE-2021-26330MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26330 [MEDIUM] CWE-122 CVE-2021-26330: AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
nvd
CVE-2021-26336MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26336 [MEDIUM] CWE-119 CVE-2021-26336: Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updat Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.
nvd
CVE-2020-12988HIGHCVSS 7.5fixed in romepi-sp3_1.0.0.c2021-06-11
CVE-2020-12988 [HIGH] CVE-2020-12988: A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
nvd