Amd Epyc 7002 Firmware vulnerabilities
26 known vulnerabilities affecting amd/epyc_7002_firmware.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM12LOW1
Vulnerabilities
Page 2 of 2
CVE-2021-26337P4MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26337 [MEDIUM] CVE-2021-26337: Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from i
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.
nvd
CVE-2021-26336P4MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26336 [MEDIUM] CWE-119 CVE-2021-26336: Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updat
Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.
nvd
CVE-2023-20523P4MEDIUMCVSS 5.7fixed in romepi_1.0.0.c2023-01-11
CVE-2023-20523 [MEDIUM] CWE-367 CVE-2023-20523: TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leadi
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
nvd
CVE-2021-26330P4MEDIUMCVSS 5.5fixed in romepi-sp3_1.0.0.c2021-11-16
CVE-2021-26330 [MEDIUM] CWE-122 CVE-2021-26330: AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
nvd
CVE-2021-26347P4MEDIUMCVSS 4.7fixed in romepi-sp3_1.0.0.d2022-05-11
CVE-2021-26347 [MEDIUM] CWE-1284 CVE-2021-26347: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attack
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
nvd
CVE-2023-20528P4LOWCVSS 2.4fixed in romepi_1.0.0.c2023-01-11
CVE-2023-20528 [LOW] CWE-20 CVE-2023-20528: Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory cont
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
nvd
← Previous2 / 2