Amd Ryzen 5 3600 Firmware vulnerabilities
5 known vulnerabilities affecting amd/ryzen_5_3600_firmware.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3
Vulnerabilities
Page 1 of 1
CVE-2022-23820CRITICALCVSS 9.8vcomboam4_pi_1.0.0.9vcomboam4_v2_pi_1.2.0.82023-11-14
CVE-2022-23820 [HIGH] CWE-20 CVE-2022-23820: Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM pote
Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution.
nvd
CVE-2022-23821CRITICALCVSS 9.8vcomboam4_pi_1.0.0.9vcomboam4_v2_pi_1.2.0.82023-11-14
CVE-2022-23821 [CRITICAL] CVE-2022-23821: Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM po
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
nvd
CVE-2023-20555HIGHCVSS 7.8fixed in comboam4_pi_v1_1.0.0.afixed in comboam4v2_pi_1.2.0.a2023-08-08
CVE-2023-20555 [HIGH] CWE-787 CVE-2023-20555: Insufficient input validation in
CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by
Insufficient input validation in
CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting
an arbitrary bit in an attacker-controlled pointer potentially leading to
arbitrary code execution in SMM.
nvd
CVE-2023-20558HIGHCVSS 8.8fixed in comboam4_v2_pi_1.2.0.6c2023-04-02
CVE-2023-20558 [HIGH] CWE-670 CVE-2023-20558:
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
nvd
CVE-2023-20559HIGHCVSS 8.8fixed in comboam4_v2_pi_1.2.0.6c2023-04-02
CVE-2023-20559 [HIGH] CWE-691 CVE-2023-20559:
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamp
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
nvd