CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 101Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+98 moreJun 17, 2026 Sep 20, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
1Amd 125Epyc 7003 Firmware Epyc 72f3 FirmwareEpyc 7313 Firmware+122 moreJun 17, 2026 Sep 20, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of...Show more |
1Amd 55Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+52 moreJun 17, 2026 May 9, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event pot...Show more |
1Amd 63Ryzen 1200 (af) Firmware Ryzen 1600 (af) FirmwareRyzen 2200g Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient input validation in ABL may enable
a privileged attacker to corrupt ASP memory, potentially resulting in a loss of
integrity or code execution.
|
1Amd 44Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+41 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation in ASP may allow
an attacker with a compromised SMM to induce out-of-bounds memory reads within
the ASP, potentially leading to a denial of service.
|
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure P...Show more |
1Amd 23Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+20 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of se...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management U...Show more |
1Amd 66Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+63 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures l...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of...Show more |