Amd Ryzen 5 4600G Firmware vulnerabilities

5 known vulnerabilities affecting amd/ryzen_5_4600g_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-26367MEDIUMCVSS 6.0fixed in comboam4v2_pi_1.2.0.52024-08-13
CVE-2021-26367 [MEDIUM] CVE-2021-26367: A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.
nvd
CVE-2023-20579MEDIUMCVSS 6.0fixed in comboam4v2pi_1.2.0.c2024-02-13
CVE-2023-20579 [MEDIUM] CWE-284 CVE-2023-20579: Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.
nvd
CVE-2023-20558HIGHCVSS 8.8fixed in renoirpi-fp6_1.0.0.72023-04-02
CVE-2023-20558 [HIGH] CWE-670 CVE-2023-20558: Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
nvd
CVE-2023-20559HIGHCVSS 8.8fixed in renoirpi-fp6_1.0.0.72023-04-02
CVE-2023-20559 [HIGH] CWE-691 CVE-2023-20559: Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamp Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
nvd
CVE-2021-26339MEDIUMCVSS 5.5fixed in comboam4_v2_pi_1.2.0.6c2022-05-11
CVE-2021-26339 [MEDIUM] CVE-2021-26339: A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated by compilers.
nvd