Amd Ryzen 5000 Series vulnerabilities
7 known vulnerabilities affecting amd/ryzen_5000_series.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-20558P3HIGHCVSS 8.8vvarious 2023-04-02
CVE-2023-20558 [HIGH] CWE-670 CVE-2023-20558: Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
nvd
CVE-2023-20559P3HIGHCVSS 8.8vvarious 2023-04-02
CVE-2023-20559 [HIGH] CWE-691 CVE-2023-20559: Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamp
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
nvd
CVE-2021-39298P3HIGHCVSS 8.8vvarious2022-02-16
CVE-2021-39298 [HIGH] CVE-2021-39298: A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacke
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
nvd
CVE-2021-26316P3HIGHCVSS 7.8vvarious 2023-01-11
CVE-2021-26316 [HIGH] CWE-20 CVE-2021-26316: Failure to validate the communication buffer and communication service in the BIOS may allow an atta
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
nvd
CVE-2021-26346P4MEDIUMCVSS 5.5vvarious 2023-01-11
CVE-2021-26346 [MEDIUM] CWE-190 CVE-2021-26346: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attack
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
nvd
CVE-2021-26347P4MEDIUMCVSS 4.7vvarious2022-05-11
CVE-2021-26347 [MEDIUM] CWE-1284 CVE-2021-26347: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attack
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
nvd
CVE-2021-46795P4MEDIUMCVSS 4.7vvarious 2023-01-11
CVE-2021-46795 [MEDIUM] CWE-367 CVE-2021-46795: A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised
A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.
nvd