Amd Epyc 7401 Firmware vulnerabilities
26 known vulnerabilities affecting amd/epyc_7401_firmware.
Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH11MEDIUM12LOW1
Vulnerabilities
Page 2 of 2
CVE-2021-26320P4MEDIUMCVSS 5.5fixed in naplespi-sp3_1.0.0.g2021-11-16
CVE-2021-26320 [MEDIUM] CWE-295 CVE-2021-26320: Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmwa
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
nvd
CVE-2021-26321P4MEDIUMCVSS 5.5fixed in naplespi-sp3_1.0.0.g2021-11-16
CVE-2021-26321 [MEDIUM] CWE-20 CVE-2021-26321: Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to p
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
nvd
CVE-2021-26330P4MEDIUMCVSS 5.5fixed in naplespi-sp3_1.0.0.g2021-11-16
CVE-2021-26330 [MEDIUM] CWE-122 CVE-2021-26330: AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
nvd
CVE-2021-26329P4MEDIUMCVSS 5.5fixed in naplespi-sp3_1.0.0.g2021-11-16
CVE-2021-26329 [MEDIUM] CWE-130 CVE-2021-26329: AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provid
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
nvd
CVE-2023-20526P4MEDIUMCVSS 4.6fixed in naplespi_1.0.0.h2023-11-14
CVE-2023-20526 [MEDIUM] CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical a
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
nvd
CVE-2021-26342P4LOWCVSS 3.3fixed in naplespi-sp3_1.0.0.h2022-05-11
CVE-2021-26342 [LOW] CVE-2021-26342: In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a parti
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV
nvd
← Previous2 / 2