Amd Ryzen 3 3250C Firmware vulnerabilities
8 known vulnerabilities affecting amd/ryzen_3_3250c_firmware.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2023-20579MEDIUMCVSS 6.0fixed in cezannepi-fp6_1.0.1.02024-02-13
CVE-2023-20579 [MEDIUM] CWE-284 CVE-2023-20579: Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode)
Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentially resulting in
loss of integrity and availability.
nvd
CVE-2022-23821CRITICALCVSS 9.8vpicassopi-fp5_1.0.0.e2023-11-14
CVE-2022-23821 [CRITICAL] CVE-2022-23821: Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM po
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
nvd
CVE-2023-20521MEDIUMCVSS 5.7fixed in picassopi-fp5_1.0.0.e2023-11-14
CVE-2023-20521 [LOW] CWE-367 CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM recor
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
nvd
CVE-2023-20594MEDIUMCVSS 4.4vcomboam4pi_1.0.0.9vcomboam4v2pi_1.2.0.82023-09-20
CVE-2023-20594 [MEDIUM] CWE-824 CVE-2023-20594: Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
nvd
CVE-2023-20597MEDIUMCVSS 5.5vcomboam4pi_1.0.0.9vcomboam4v2pi_1.2.0.82023-09-20
CVE-2023-20597 [MEDIUM] CWE-824 CVE-2023-20597: Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
nvd
CVE-2021-26365HIGHCVSS 8.2fixed in picassopi-fp5_1.0.0.d2023-05-09
CVE-2021-26365 [HIGH] CWE-125 CVE-2021-26365: Certain size values in firmware binary headers
could trigger out of bounds reads during signature va
Certain size values in firmware binary headers
could trigger out of bounds reads during signature validation, leading to
denial of service or potentially limited leakage of information about
out-of-bounds memory contents.
nvd
CVE-2021-26354MEDIUMCVSS 5.5fixed in picassopi-fp5_1.0.0.d2023-05-09
CVE-2021-26354 [MEDIUM] CWE-120 CVE-2021-26354: Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised
Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
nvd
CVE-2021-26371MEDIUMCVSS 5.5fixed in picassopi-fp5_1.0.0.d2023-05-09
CVE-2021-26371 [MEDIUM] CVE-2021-26371: A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
nvd